5
CVSSv2

CVE-2009-4170

Published: 02/12/2009 Updated: 10/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote malicious users to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which reveals the installation path in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

roytanck wp-cumulus 1.20

Exploits

I want to warn you about security vulnerabilities in plugin WP-Cumulus for WordPress These are Full path disclosure and Cross-Site Scripting vulnerabilities Full path disclosure: server/wp-content/plugins/wp-cumulus/wp-cumulusphp XSS: server/wp-content/plugins/wp-cumulus/tagcloudswf?mode=tags&tagcloud=%3Ctags%3E%3Ca+href= ...