CVE-2021-24227: Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusion

CVE-2021-24227: Patreon WordPress  <1.7.0 - Unauthenticated Local File Inclusion-渗透云记 - 专注于网络安全与技术分享
CVE-2021-24227: Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusion
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-24227: Patreon WordPress <1.7.0 – Unauthenticated Local File Inclusion

漏洞描述

Patreon WordPress before version 1.7.0 is vulnerable to unauthenticated local file inclusion that could be abused by anyone visiting the site. Exploitation by an attacker could leak important internal files like wp-config.php, which contains database credentials and cryptographic keys used in the generation of nonces and cookies.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享