mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-03 12:58:02 +02:00
28 lines
1.2 KiB
Markdown
28 lines
1.2 KiB
Markdown
### [CVE-2020-24312](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24312)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
No PoCs from references.
|
|
|
|
#### Github
|
|
- https://github.com/ARPSyndicate/kenzer-templates
|
|
- https://github.com/Elsfa7-110/kenzer-templates
|
|
- https://github.com/StarCrossPortal/scalpel
|
|
- https://github.com/anonymous364872/Rapier_Tool
|
|
- https://github.com/apif-review/APIF_tool_2024
|
|
- https://github.com/d4n-sec/d4n-sec.github.io
|
|
- https://github.com/merlinepedra/nuclei-templates
|
|
- https://github.com/merlinepedra25/nuclei-templates
|
|
- https://github.com/sobinge/nuclei-templates
|
|
- https://github.com/youcans896768/APIV_Tool
|
|
- https://github.com/zer0detail/Echidna
|
|
|