5
CVSSv2

CVE-2017-11658

Published: 26/07/2017 Updated: 04/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In the WP Rocket plugin 2.9.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal characters (..) -- however, this is insufficient to stop remote attacks and can be bypassed by using 0x00 bytes, as demonstrated by a .%00.../.%00.../ attack.

Vulnerable Product Search on Vulmon Subscribe to Product

wp-rocket wp-rocket 2.9.11

wp-rocket wp-rocket 2.9.10

wp-rocket wp-rocket 2.9.9

wp-rocket wp-rocket 2.9.8.1

wp-rocket wp-rocket 2.8.18

wp-rocket wp-rocket 2.8.17

wp-rocket wp-rocket 2.8.16

wp-rocket wp-rocket 2.8.15

wp-rocket wp-rocket 2.8.1

wp-rocket wp-rocket 2.8.0

wp-rocket wp-rocket 2.7.4

wp-rocket wp-rocket 2.7.3

wp-rocket wp-rocket 2.6.7

wp-rocket wp-rocket 2.6.6

wp-rocket wp-rocket 2.6.5

wp-rocket wp-rocket 2.6.4

wp-rocket wp-rocket 2.5.3

wp-rocket wp-rocket 2.5.2

wp-rocket wp-rocket 2.5.1

wp-rocket wp-rocket 2.5.0

wp-rocket wp-rocket 2.3.1

wp-rocket wp-rocket 2.3.0

wp-rocket wp-rocket 2.2.3

wp-rocket wp-rocket 2.2.2

wp-rocket wp-rocket 1.3.5

wp-rocket wp-rocket 1.3.4

wp-rocket wp-rocket 1.3.3

wp-rocket wp-rocket 1.3.2

wp-rocket wp-rocket 1.3.1

wp-rocket wp-rocket 2.9.3

wp-rocket wp-rocket 2.9.2

wp-rocket wp-rocket 2.9.1

wp-rocket wp-rocket 2.9.0

wp-rocket wp-rocket 2.8.10

wp-rocket wp-rocket 2.8.9

wp-rocket wp-rocket 2.8.8

wp-rocket wp-rocket 2.8.7

wp-rocket wp-rocket 2.6.15

wp-rocket wp-rocket 2.6.14

wp-rocket wp-rocket 2.6.13

wp-rocket wp-rocket 2.6.12

wp-rocket wp-rocket 2.5.11

wp-rocket wp-rocket 2.5.10

wp-rocket wp-rocket 2.5.9

wp-rocket wp-rocket 2.5.8

wp-rocket wp-rocket 2.3.10

wp-rocket wp-rocket 2.3.9

wp-rocket wp-rocket 2.3.8

wp-rocket wp-rocket 2.3.7

wp-rocket wp-rocket 2.3.6

wp-rocket wp-rocket 2.0.5

wp-rocket wp-rocket 2.0.4

wp-rocket wp-rocket 2.0.3

wp-rocket wp-rocket 2.0.2

wp-rocket wp-rocket 2.10.3

wp-rocket wp-rocket 2.10.1

wp-rocket wp-rocket 2.9.7

wp-rocket wp-rocket 2.9.5

wp-rocket wp-rocket 2.8.21

wp-rocket wp-rocket 2.8.19

wp-rocket wp-rocket 2.8.14

wp-rocket wp-rocket 2.8.12

wp-rocket wp-rocket 2.8.5

wp-rocket wp-rocket 2.8.3

wp-rocket wp-rocket 2.7.1

wp-rocket wp-rocket 2.6.16

wp-rocket wp-rocket 2.6.11

wp-rocket wp-rocket 2.6.9

wp-rocket wp-rocket 2.6.2

wp-rocket wp-rocket 2.6.0

wp-rocket wp-rocket 2.5.6

wp-rocket wp-rocket 2.5.4

wp-rocket wp-rocket 2.4.2

wp-rocket wp-rocket 2.4.0

wp-rocket wp-rocket 2.3.5

wp-rocket wp-rocket 2.3.3

wp-rocket wp-rocket 2.2.0

wp-rocket wp-rocket 2.1.0

wp-rocket wp-rocket 2.0.1

wp-rocket wp-rocket 1.3.7

wp-rocket wp-rocket 1.3.0

wp-rocket wp-rocket 2.10.2

wp-rocket wp-rocket 2.10.0

wp-rocket wp-rocket 2.9.8

wp-rocket wp-rocket 2.9.6

wp-rocket wp-rocket 2.9.4

wp-rocket wp-rocket 2.8.23

wp-rocket wp-rocket 2.8.20

wp-rocket wp-rocket 2.8.13

wp-rocket wp-rocket 2.8.11

wp-rocket wp-rocket 2.8.6

wp-rocket wp-rocket 2.8.4

wp-rocket wp-rocket 2.8.2

wp-rocket wp-rocket 2.7.2

wp-rocket wp-rocket 2.7.0

wp-rocket wp-rocket 2.6.10

wp-rocket wp-rocket 2.6.8

wp-rocket wp-rocket 2.6.3

wp-rocket wp-rocket 2.6.1.1

wp-rocket wp-rocket 2.5.12

wp-rocket wp-rocket 2.5.7

wp-rocket wp-rocket 2.5.5

wp-rocket wp-rocket 2.4.1

wp-rocket wp-rocket 2.3.11

wp-rocket wp-rocket 2.3.4

wp-rocket wp-rocket 2.3.2

wp-rocket wp-rocket 2.2.1

wp-rocket wp-rocket 2.1.1

wp-rocket wp-rocket 2.0.0

wp-rocket wp-rocket 1.3.6