7.5
CVSSv2

CVE-2008-1060

Published: 28/02/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote malicious users to execute arbitrary PHP code via the text parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress sniplets plugin 1.2.2

wordpress sniplets plugin 1.1.2

Exploits

######################## Wordpress Plugin Sniplets 112 Multiple Vulnerabilities by NBBN ######################## 1) Remote File Inclusion File: /modules/syntax_highlightphp Register Globals: ON Vuln code: <?php /* Name: Syntax Highlight */ include_once ("$libpath/geshi/geshiphp"); Poc: victimtld/wordpress/wp-content/plugins/sniple ...