Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
WordPress-Path-Traversal-CVE-2019-11447 — Detailed penetration test report demonstrating unauthenticated path traversal (CVE-2019-11447) in WordPress Simple Backup plugin, including exploitation steps, impact analysis, and remediation guidance. | Kitploit
उपकरण/GitHubGitHub/capivara-research/wordpress-path-traversal-cve-2019-11447
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationLabs & Practice
GitHubcapivara-research/wordpress-path-traversal-cve-2019-11447

WordPress-Path-Traversal-CVE-2019-11447

Detailed penetration test report demonstrating unauthenticated path traversal (CVE-2019-11447) in WordPress Simple Backup plugin, including exploitation steps, impact analysis, and remediation guidance.

रिपॉजिटरी देखें
1717 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

Penetration Test Report

WordPress Path Traversal - CVE-2019-11447


Document Information

ItemDetails
Document TitlePenetration Test Report - WordPress Path Traversal
Client/ExamHackTheBox Lab - CPTS Exercise 1
DateAugust 22, 2026
AssessorFernando Viana (Penetration Tester)
Assessment TypeGray Box (External, No Credentials)
Lab Environment154.57.164.73:30706
Lab Duration1 Hour
ObjectivesIdentify and exploit vulnerabilities to retrieve restricted files
Flag ObtainedHTB{my_f1r57_h4ck}

Executive Summary

During this penetration assessment of the web application hosted on 154.57.164.73:30706, a critical vulnerability was identified that allows unauthenticated attackers to download and read arbitrary files from the server filesystem.

The vulnerable WordPress installation contains an outdated plugin (Simple Backup v2.7.10) with a path traversal vulnerability (CVE-2019-11447) that permits unauthorized file access without requiring authentication or authorization.

This vulnerability was successfully exploited to retrieve the /flag.txt file from the server root, confirming complete compromise of confidentiality. An attacker with this access could:

  • Extract sensitive configuration files (wp-config.php, .env)
  • Read database credentials and user data
  • Access private SSH keys and authentication tokens
  • Potentially escalate privileges through leaked credentials
  • Harvest personal information for further attacks

Critical action is required to remediate this vulnerability immediately, as it poses an extreme risk to data security, privacy compliance (GDPR, HIPAA, PCI-DSS), and system integrity.


Assessment Overview

SeverityCountBusiness Impact
🔴 CRITICAL1Complete confidentiality breach; unauthorized file access
🟠 HIGH0—
🟡 MEDIUM0—
🟢 LOW0—
ℹ️ INFORMATIONAL1Outdated software versions detected

Methodology

Assessment Type: Gray Box (external attacker, no credentials provided, network access available)

Assessment Dates: August 22, 2026

Testing Approach: Non-evasive, methodical assessment following industry-standard penetration testing framework (PTES):

  1. Reconnaissance — Passive information gathering
  2. Scanning & Enumeration — Active service discovery
  3. Vulnerability Analysis — Identification of weaknesses
  4. Exploitation — Proof of concept development
  5. Post-Exploitation — Impact demonstration
  6. Reporting — Documentation and remediation guidance

Findings

🔴 CRITICAL - Path Traversal & Arbitrary File Download

CVE-2019-11447 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory


Description

The WordPress plugin Simple Backup (version 2.7.10/2.7.11, Exploit-DB 39883) contains a path traversal vulnerability in its admin "Backup Manager" page. The plugin fails to sanitize the file path supplied through the download_backup_file GET parameter, allowing an attacker to traverse outside the intended simple-backup/ directory using relative path sequences (../) and download any file readable by the web server process — including files at the filesystem root.

The vulnerable endpoint:

GET /wp-admin/tools.php?page=backup_manager&download_backup_file=../../../../../../../../../../flag.txt

page=backup_manager routes the request into the plugin's admin page handler; download_backup_file is the parameter the plugin's code reads directly and concatenates into a filesystem path without validation, allowing directory traversal.


CVSS v3.1 Score

7.5 - HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

  • Attack Vector (AV): Network
  • Attack Complexity (AC): Low
  • Privileges Required (PR): None
  • User Interaction (UI): None
  • Scope (S): Unchanged
  • Confidentiality (C): High
  • Integrity (I): None
  • Availability (A): None

Business Impact

Confidentiality Breach: ⚠️ CRITICAL

Attackers can read any file accessible to the web server, including:

FileImpactRisk Level
/wp-config.phpDatabase credentials, salts, keys🔴 CRITICAL
/.envAPI keys, secrets, configuration🔴 CRITICAL
/etc/passwdUser enumeration, system mapping🟠 HIGH
SSH keys (.ssh/id_rsa)Lateral movement, system access🔴 CRITICAL
/proc/self/environRunning application secrets🟠 HIGH
User uploads directoryPrivate files, media🟠 HIGH

Regulatory Impact:

  • GDPR Violation: Unauthorized access to user data
  • HIPAA Violation: Protected health information exposure
  • PCI-DSS Violation: Credit card data or payment info access
  • SOC 2 Violation: Confidentiality requirement breach

Vulnerable Code Pattern

The Exploit-DB advisory (39883.txt, read via searchsploit -x — see ht4-poc.png) documents the plugin's delete primitive from simple-backup-manager.php:

if(array_key_exists('delete_backup_file', $_GET)){
    $this->delete_local_backup_file($_GET['delete_backup_file']);
}
$bk_dir = ABSPATH."simple-backup/";
unlink($bk_dir . $filename);

$filename comes straight from $_GET['delete_backup_file'] with no basename() or path-containment check. Passing ../pizza.txt resolves $bk_dir . $filename to .../simple-backup/../pizza.txt → .../pizza.txt, escaping the intended backup folder.

The download primitive actually exploited in this engagement (download_backup_file) follows the exact same unsanitized concatenation pattern in the same plugin, but serves the file back to the requester instead of deleting it — which is what allowed retrieval of /flag.txt from the filesystem root (10× ../ from ABSPATH/simple-backup/).

The Problem:

  • No use of basename() to remove directory components
  • No whitelist of allowed files
  • No validation that realpath() stays within ABSPATH."simple-backup/"
  • Direct concatenation of user input into the file path
  • No current_user_can() / authentication check before serving the file — the handler runs on plugin load, before WordPress's own wp-admin auth gate, so it is reachable without being logged in

Proof of Concept

Phase 1: Initial Access — Application Identification

Connected directly to the target via browser (http://154.57.164.73:30706/). The WordPress installation is titled "GETTING STARTED", and a public blog post on the homepage discloses the exact plugin name and version in plain text: "Simple Backup Plugin 2.7.10 for WordPress" — no enumeration tooling was even required to fingerprint the vulnerable component.

Initial Access - Plugin version disclosed on WordPress homepage

Phase 2: Service Fingerprinting

whatweb http://154.57.164.73:30706/

Result: Apache/2.4.41 (Ubuntu Linux), WordPress 5.6.1 confirmed via MetaGenerator and WordPress plugin signatures.

Service Fingerprinting - whatweb output

Phase 3: Vulnerability Research

searchsploit simple backup wordpress
टूल डाउनलोड करें