Description
Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the imgname parameter. Attackers can send requests to asgallDownload.php with directory traversal sequences ../ to access sensitive files outside the intended directory.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
Ihsan Sencan
References
www.exploit-db.com/exploits/41568 (ExploitDB-41568)
www.apptha.com/ (Official Product Homepage)
www.vulncheck.com/...er-gallery-path-traversal-file-download (VulnCheck Advisory: WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download)