WordPress Plugin Vulnerabilities
File Manager < 5.0.2 - Information Disclosure
Description
The Giribaz File Manager plugin logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If user edits wp-config.php file using this plugin, the wp-config.php contents get added to the file which is not protected and contains database credentials, salts, etc. These files have been indexed by Google and an simple dork will find affected sites.
Proof of Concept
Affects Plugins
References
Classification
Type
FPD
OWASP top 10
CWE
CVSS
Miscellaneous
Submitter
Colette Chamberland
Submitter website
Submitter twitter
Verified
No
WPVDB ID
Timeline
Publicly Published
2018-03-02 (about 8 years ago)
Added
2018-03-02 (about 8 years ago)
Last Updated
2020-09-22 (about 5 years ago)