CVE-2020-35749: WordPress Simple Job Board <2.9.4 - Local File Inclusion

CVE-2020-35749: WordPress Simple Job Board <2.9.4 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享
CVE-2020-35749: WordPress Simple Job Board <2.9.4 - Local File Inclusion
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2020-35749: WordPress Simple Job Board <2.9.4 – Local File Inclusion

漏洞描述

WordPress Simple Job Board prior to version 2.9.4 is vulnerable to arbitrary file retrieval vulnerabilities because it does not validate the sjb_file parameter when viewing a resume, allowing an authenticated user with the download_resume capability (such as HR users) to download arbitrary files from the web-server via local file inclusion.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享