7.5

CVE-2017-11658

Exploit

In the WP Rocket plugin 2.9.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal characters (..) -- however, this is insufficient to stop remote attacks and can be bypassed by using 0x00 bytes, as demonstrated by a .%00.../.%00.../ attack.

Data is provided by the National Vulnerability Database (NVD)
Wp-rocketWp-rocket Version1.3.0 SwPlatformwordpress
Wp-rocketWp-rocket Version1.3.1 SwPlatformwordpress
Wp-rocketWp-rocket Version1.3.2 SwPlatformwordpress
Wp-rocketWp-rocket Version1.3.3 SwPlatformwordpress
Wp-rocketWp-rocket Version1.3.4 SwPlatformwordpress
Wp-rocketWp-rocket Version1.3.5 SwPlatformwordpress
Wp-rocketWp-rocket Version1.3.6 SwPlatformwordpress
Wp-rocketWp-rocket Version1.3.7 SwPlatformwordpress
Wp-rocketWp-rocket Version2.0.0 SwPlatformwordpress
Wp-rocketWp-rocket Version2.0.1 SwPlatformwordpress
Wp-rocketWp-rocket Version2.0.2 SwPlatformwordpress
Wp-rocketWp-rocket Version2.0.3 SwPlatformwordpress
Wp-rocketWp-rocket Version2.0.4 SwPlatformwordpress
Wp-rocketWp-rocket Version2.0.5 SwPlatformwordpress
Wp-rocketWp-rocket Version2.1.0 SwPlatformwordpress
Wp-rocketWp-rocket Version2.1.1 SwPlatformwordpress
Wp-rocketWp-rocket Version2.2.0 SwPlatformwordpress
Wp-rocketWp-rocket Version2.2.1 SwPlatformwordpress
Wp-rocketWp-rocket Version2.2.2 SwPlatformwordpress
Wp-rocketWp-rocket Version2.2.3 SwPlatformwordpress
Wp-rocketWp-rocket Version2.3.0 SwPlatformwordpress
Wp-rocketWp-rocket Version2.3.1 SwPlatformwordpress
Wp-rocketWp-rocket Version2.3.2 SwPlatformwordpress
Wp-rocketWp-rocket Version2.3.3 SwPlatformwordpress
Wp-rocketWp-rocket Version2.3.4 SwPlatformwordpress
Wp-rocketWp-rocket Version2.3.5 SwPlatformwordpress
Wp-rocketWp-rocket Version2.3.6 SwPlatformwordpress
Wp-rocketWp-rocket Version2.3.7 SwPlatformwordpress
Wp-rocketWp-rocket Version2.3.8 SwPlatformwordpress
Wp-rocketWp-rocket Version2.3.9 SwPlatformwordpress
Wp-rocketWp-rocket Version2.3.10 SwPlatformwordpress
Wp-rocketWp-rocket Version2.3.11 SwPlatformwordpress
Wp-rocketWp-rocket Version2.4.0 SwPlatformwordpress
Wp-rocketWp-rocket Version2.4.1 SwPlatformwordpress
Wp-rocketWp-rocket Version2.4.2 SwPlatformwordpress
Wp-rocketWp-rocket Version2.5.0 SwPlatformwordpress
Wp-rocketWp-rocket Version2.5.1 SwPlatformwordpress
Wp-rocketWp-rocket Version2.5.2 SwPlatformwordpress
Wp-rocketWp-rocket Version2.5.3 SwPlatformwordpress
Wp-rocketWp-rocket Version2.5.4 SwPlatformwordpress
Wp-rocketWp-rocket Version2.5.5 SwPlatformwordpress
Wp-rocketWp-rocket Version2.5.6 SwPlatformwordpress
Wp-rocketWp-rocket Version2.5.7 SwPlatformwordpress
Wp-rocketWp-rocket Version2.5.8 SwPlatformwordpress
Wp-rocketWp-rocket Version2.5.9 SwPlatformwordpress
Wp-rocketWp-rocket Version2.5.10 SwPlatformwordpress
Wp-rocketWp-rocket Version2.5.11 SwPlatformwordpress
Wp-rocketWp-rocket Version2.5.12 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.0 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.1.1 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.2 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.3 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.4 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.5 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.6 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.7 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.8 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.9 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.10 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.11 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.12 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.13 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.14 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.15 SwPlatformwordpress
Wp-rocketWp-rocket Version2.6.16 SwPlatformwordpress
Wp-rocketWp-rocket Version2.7.0 SwPlatformwordpress
Wp-rocketWp-rocket Version2.7.1 SwPlatformwordpress
Wp-rocketWp-rocket Version2.7.2 SwPlatformwordpress
Wp-rocketWp-rocket Version2.7.3 SwPlatformwordpress
Wp-rocketWp-rocket Version2.7.4 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.0 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.1 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.2 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.3 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.4 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.5 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.6 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.7 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.8 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.9 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.10 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.11 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.12 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.13 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.14 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.15 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.16 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.17 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.18 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.19 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.20 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.21 SwPlatformwordpress
Wp-rocketWp-rocket Version2.8.23 SwPlatformwordpress
Wp-rocketWp-rocket Version2.9.0 SwPlatformwordpress
Wp-rocketWp-rocket Version2.9.1 SwPlatformwordpress
Wp-rocketWp-rocket Version2.9.2 SwPlatformwordpress
Wp-rocketWp-rocket Version2.9.3 SwPlatformwordpress
Wp-rocketWp-rocket Version2.9.4 SwPlatformwordpress
Wp-rocketWp-rocket Version2.9.5 SwPlatformwordpress
Wp-rocketWp-rocket Version2.9.6 SwPlatformwordpress
Wp-rocketWp-rocket Version2.9.7 SwPlatformwordpress
Wp-rocketWp-rocket Version2.9.8 SwPlatformwordpress
Wp-rocketWp-rocket Version2.9.8.1 SwPlatformwordpress
Wp-rocketWp-rocket Version2.9.9 SwPlatformwordpress
Wp-rocketWp-rocket Version2.9.10 SwPlatformwordpress
Wp-rocketWp-rocket Version2.9.11 SwPlatformwordpress
Wp-rocketWp-rocket Version2.10.0 SwPlatformwordpress
Wp-rocketWp-rocket Version2.10.1 SwPlatformwordpress
Wp-rocketWp-rocket Version2.10.2 SwPlatformwordpress
Wp-rocketWp-rocket Version2.10.3 SwPlatformwordpress
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.03% 0.854
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.