VulnerabilityModified
CVE-2012-0896
Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.
MEDIUM 5.0EPSS 22.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 22.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 22.66% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- count per day project/count per day · tom braider/count per day
- Source
- cve@mitre.org
References
- http://osvdb.org/78270Exploit
- http://packetstormsecurity.org/files/108631/countperday-downloadxss.txtExploit
- http://plugins.trac.wordpress.org/changeset/488883/count-per-day
- http://secunia.com/advisories/47529Vendor Advisory
- http://wordpress.org/extend/plugins/count-per-day/changelog/
- http://www.exploit-db.com/exploits/18355Exploit
- http://www.securityfocus.com/bid/51402
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72385
- http://osvdb.org/78270Exploit
- http://packetstormsecurity.org/files/108631/countperday-downloadxss.txtExploit
- http://plugins.trac.wordpress.org/changeset/488883/count-per-day
- http://secunia.com/advisories/47529Vendor Advisory
- http://wordpress.org/extend/plugins/count-per-day/changelog/
- http://www.exploit-db.com/exploits/18355Exploit
- http://www.securityfocus.com/bid/51402
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72385
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.