Lucene search

K
wpexploitAlex SanfordWPEX-ID:3B7A7070-8D61-4FF8-B003-B4FF06221635
HistorySep 25, 2023 - 12:00 a.m.

NextGEN Gallery < 3.39 - Admin+ Local File Inclusion

2023-09-2500:00:00
Alex Sanford
65
local file inclusion
nextgen gallery
admin+
customize display settings
developer tools
exploit

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

23.9%

Description The plugin does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks

1. Create a gallery and upload an image.
2. Add the NextGEN Gallery block to a page and click Edit. Select the Gallery created in the previous step.
3. In "Customize Display Settings", using the developer tools, set the value of the "Select View" field to "default/../../../../../../../../../../../../../../../../../../../../../../../../../../../../etc/passwd"
4. Save and load the page to view the contents of `/etc/passwd`.

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

23.9%

Related for WPEX-ID:3B7A7070-8D61-4FF8-B003-B4FF06221635