vendor:
S3Bubble Cloud Video With Adverts & Analytics
by:
CrashBandicot
7.5
CVSS
HIGH
Arbitrary File Download
434
CWE
Product Name: S3Bubble Cloud Video With Adverts & Analytics
Affected Version From: 0.7
Affected Version To: 0.7
Patch Exists: YES
Related CWE: N/A
CPE: a:s3bubble:s3bubble_cloud_video_with_adverts_and_analytics
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: MSWin32
2015
WordPress S3Bubble Cloud Video With Adverts & Analytics – Arbitrary File Download
A vulnerability in the Wordpress S3Bubble Cloud Video With Adverts & Analytics plugin allows an attacker to download arbitrary files from the server. This is due to the downloader.php script in the plugin which allows an attacker to specify a file path in the 'path' parameter and download the file. This can be exploited by an attacker to download sensitive files such as the wp-config.php file which contains the database credentials.
Mitigation:
Upgrade to the latest version of the plugin.