WordPress Trinity Theme 'download. php' Arbitrary File download Vulnerability
Release date:
Updated on:
Affected Systems:
WordPress Trinity
Description:
Bugtraq id: 69759
WordPress Trinity is a business theme with four different la S.
The WordPress Trinity topic has the Arbitrary File Download Vulnerability. Attackers can exploit this vulnerability to download arbitrary files from web servers.
<* Source: Mr. Doel
*>
Test method:
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Mr. Doel () provides the following test methods:
Http://www.example.com/wp-content/themes/trinity/lib/scripts/download.php? File =/etc/passwd
Suggestion:
Vendor patch:
WordPress
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://wordpress.org/
This article permanently updates the link address: