WP Vault 0.8.6.6 – Local File Inclusion

Homepage: https://wordpress.org/plugins/wp-vault/ Description: Type user access: any user. $_GET[“wpv-image”] is not escaped in include file. File / Code: Path: /wp-content/plugins/wp-vault/trunk/wp-vault.php Line: 228 include(dirname(__FILE__) . “/images/” . $_GET[“wpv-image”]); if (isset($_GET[“wpv_file_id”])) { include(dirname(__FILE__) . “/wpv-file-handler.php”); exit; } else if (isset($_POST[“wpv-tooltip”])) { include(dirname(__FILE__) . “/ajax-response/wpv-tooltip.php”); exit; } else if (isset($_GET[“wpv-image”])) { include(dirname(__FILE__) . “/images/” . $_GET[“wpv-image”]); exit; } else … Continue reading WP Vault 0.8.6.6 – Local File Inclusion