漏洞描述
An absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
packetstormsecurity.comhttps://packetstormsecurity.com/files/108631/↗plugins.trac.wordpress.orghttp://plugins.trac.wordpress.org/changeset/488883/count-per-day↗httpshttps://https://nvd.nist.gov/vuln/detail/CVE-2012-0896↗wordpress.orghttp://wordpress.org/extend/plugins/count-per-day/changelog/↗exchange.xforce.ibmcloud.comhttps://exchange.xforce.ibmcloud.com/vulnerabilities/72385↗