MiwoFTP < 1.0.5 - Arbitrary File Download

2015-04-14 00:00
James Hooker

Strategic Overview

Status
Patched in 1.0.5
Affected Pluginmiwoftp
Affected Version< 1.0.5
CVSS8.6High
CVEN/A
View all miwoftp vulnerabilities

Vulnerability Overview

The MiwoFTP plugin for WordPress is vulnerable to Arbitrary File Download in versions before 1.0.5. This is due to the improper use of a hook which utilizes a download file function. This makes it possible for unauthenticated attackers to arbitrarily download files located within the home directory of the affected site.

Technical Analysis

REMEDIATION: Update to version 1.0.5, or a newer patched version --- IDENTIFIER: CWE-552 (Files or Directories Accessible to External Parties) The product makes files or directories accessible to unauthorized actors, even though they should not be.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C