Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

G0Blin

#19052of 53,625
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2023-10284
6.5
2023-05-01
WordPress · Ip Blacklist Cloud Plugin · CVE-2015-10105
**Name of the Vulnerable Software and Affected Versions** IP Blacklist Cloud Plugin versions up to 3.42 **Description** A critical vulnerability was found in the IP Blacklist Cloud Plugin on WordPress, affecting the `valid js identifier` function of the `ip blacklist cloud.php` file in the CSV File Import component. The manipulation of the `filename` argument leads to path traversal, and it is possible to initiate the attack remotely. **Recommendations** For IP Blacklist Cloud Plugin versions up to 3.42, upgrade to version 3.43 to address this issue. As a temporary workaround, consider restricting access to the `ip blacklist cloud.php` file or disabling the `valid js identifier` function until the upgrade is applied.
PT-2014-7222
7.5
2014-09-26
Infusionsoft · Infusionsoft Gravity Forms · CVE-2014-6446
**Name of the Vulnerable Software and Affected Versions** Infusionsoft Gravity Forms plugin versions 1.5.3 through 1.5.10 **Description** The issue allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to "utilities/code generator.php". This is due to improper access restriction. **Recommendations** For versions 1.5.3 through 1.5.10, consider restricting access to the "utilities/code generator.php" endpoint until a patch is available.