Lucene search

K
wpvulndbColette ChamberlandWPVDB-ID:F37A3E8B-292A-4C07-8F18-9621AC160810
HistoryMar 02, 2018 - 12:00 a.m.

File Manager <= 5.0.0 - Information Disclosure

2018-03-0200:00:00
Colette Chamberland
wpscan.com
4

0.002 Low

EPSS

Percentile

52.0%

The Giribaz File Manager plugin logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If user edits wp-config.php file using this plugin, the wp-config.php contents get added to the file which is not protected and contains database credentials, salts, etc. These files have been indexed by Google and an simple dork will find affected sites.

PoC

http://[target]/wp-content/uploads/file-manager/log.txt

CPENameOperatorVersion
file-managerlt5.0.2

0.002 Low

EPSS

Percentile

52.0%

Related for WPVDB-ID:F37A3E8B-292A-4C07-8F18-9621AC160810