Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Henrisalo

#26938de 53,635
9.3CVSS total
Vulnerabilidades · 2
Média
2
PT-2014-3299
5.0
2014-01-02
WordPress · Advanced Dewplayer Plugin · CVE-2013-7240
**Name of the Vulnerable Software and Affected Versions** Advanced Dewplayer plugin version 1.2 for WordPress **Description** The issue allows remote attackers to read arbitrary files via a .. (dot dot) in the `dew file` parameter in the download-file.php file. **Recommendations** For Advanced Dewplayer plugin version 1.2, consider restricting access to the download-file.php file until a patch is available, or avoid using the `dew file` parameter in the affected endpoint.
PT-2012-2159
4.3
2012-09-20
WordPress · Wordpress · CVE-2011-5182
**Name of the Vulnerable Software and Affected Versions** Lanoba Social plugin version 1.0 **Description** A cross-site scripting (XSS) issue in the Lanoba Social plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the `action` parameter in lanoba-social-plugin/index.php. The vendor disputes this issue, stating that the plugin sanitizes user input and this input is never sent to the browser, thus an attacker has no way of executing script or code on a user's behalf. **Recommendations** For Lanoba Social plugin version 1.0, consider restricting access to the `action` parameter in lanoba-social-plugin/index.php to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.