.. / CVE-2015-1000010

Exploit for WordPress Simple Image Manipulator < 1.0 - Local File Inclusion (CVE-2015-1000010)

Description:

WordPress Simple Image Manipulator 1.0 is vulnerable to local file inclusion in ./simple-image-manipulator/controller/download.php because no checks are made to authenticate users or sanitize input when determining file location.

Nuclei Template

View the template here CVE-2015-1000010.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2015/CVE-2015-1000010.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2015-1000010
https://wpscan.com/vulnerability/40e84e85-7176-4552-b021-6963d0396543
http://www.vapidlabs.com/advisory.php?v=147
https://packetstormsecurity.com/files/132962/WordPress-Simple-Image-Manipulator-1.0-File-Download.html