Ajax Load More <= 2.11.1 - Local File Inclusion (LFI)
Description | NOTE: The victim should have the paid add-on Custom Repeater or Unlimited installed. |
Affects Plugin
fixed in version 2.11.2
|
References
URL | http://seclists.org/fulldisclosure/2016/Aug/72 |
URL | https://sumofpwn.nl/advisory/2016/ajax_load_more_local_file_inclusion_vulnerability.html |
Classification
Type | LFI |
OWASP Top 10 | A1: Injection |
CWE | CWE-22 |
Miscellaneous
Submitter | ethicalhack3r |
Submitter Website | https://dewhurstsecurity.com/ |
Submitter Twitter | ethicalhack3r |
Views | 2005 |
Verified | No |
WPVDB ID | 8603 |
Timeline
Publicly Published | 2016-08-15 (over 2 years ago) |
Added | 2016-08-16 (over 2 years ago) |
Last Updated | 2016-08-16 (over 2 years ago) |
Copyright & License
Copyright | All data and resources contained within this page and this web site is Copyright © The WPScan Team. |
License | Some of this data may be used for non-commercial purposes, however, any potential commercial usage of this data will require a license. If you would like to inquire about a commercial license please contact us. |