S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2017-1000170 Scanner

CVE-2017-1000170 scanner - Directory Traversal vulnerability in Delightful Downloads Jquery File Tree plugin for WordPress

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-1000170
7.5
CVSS

jqueryFileTree 2.1.5 and older Directory Traversal

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

Delightful Downloads Jquery File Tree is a plugin built for WordPress websites that provides an easy way to display files and folders in a directory tree view. This plugin has been provided as an open-source solution, allowing users to access all the necessary files and folders through an interactive interface. Users can customize the plugin to suit their specific needs for their website, making it a widely used solution in the WordPress community.

One of the commonly known security vulnerabilities that have been detected in the Delightful Downloads Jquery File Tree plugin for WordPress is the CVE-2017-1000170 vulnerability. It is a directory traversal vulnerability where an attacker can exploit the plugin to bypass security restrictions and access files and folders outside of the intended directory. The attacker can also write files and run arbitrary codes, thus compromising the website's security.

If the CVE-2017-1000170 vulnerability is exploited, it can lead to a range of security issues such as loss of data, deletion of files, and unauthorized access to sensitive information. The data breach can result in reputational loss, financial loss, and legal complications. Exploiting this vulnerability can give attackers the opportunity to gain access to protected information and use it for malicious activities such as identity theft and phishing attacks.

Thanks to the pro features of the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets. The platform provides real-time monitoring and alert features that enable website owners to identify and address security vulnerabilities before they cause any damage. The platform also provides automated scans and reports that can detect and notify users about any issues on their website, ensuring that they take immediate action to safeguard their website's security. In conclusion, website owners must prioritize website security and invest in the necessary tools and resources to keep their digital assets safe from cyber threats.

 

REFERENCES

Solution Advice

There are several precautions that website owners can take to protect their websites from this vulnerability, including:

  • Always keeping the software up-to-date with the latest patch releases
  • Implementing access controls to restrict access to sensitive files and directories
  • Implementing intrusion prevention software to detect and block attacks
  • Performing regular backups of all website data
  • Disabling directory browsing on the webserver configurations

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-1000170 scanner - Directory Traversal vulnerability in Delightful Downloads Jquery File Tree plugin for WordPress | S4E