🔙 목록으로 돌아가기

CVE-2020-36705: Adning Advertising <= 1.5.5 - Arbitrary File Upload

TitleAdning Advertising <= 1.5.5 - Arbitrary File Upload
AuthorDhiyaneshDK
SeverityCritical
ImpactUnauthenticated attackers can upload malicious files to achieve remote code execution, potentially compromising the entire WordPress site and server.
RemediationFixed in 1.5.6
CVSS Score9.8
EPSS Score0.8533
CVE IDCVE-2020-36705
Tags cve cve2020 wordpress wp-plugin angwp wp passive vkev vuln

🔍 Vulnerability Description

The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

🌐 HTTP Request

GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-36705.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-36705.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A