5
CVSSv2

CVE-2015-5065

Published: 24/06/2015 Updated: 03/07/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin prior to 1.4 for WordPress allows remote malicious users to read arbitrary files via a full pathname in the requrl parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

intelligent-it paypal currency converter basic for woocommerce

Exploits

# Exploit Title: Paypal Currency Converter Basic For Woocommerce File Read # Google Dork: inurl:"paypal-currency-converter-basic-for-woocommerce" # Date: 10/06/2015 # Exploit Author: Kuroi'SH # Software Link: wordpressorg/plugins/paypal-currency-converter-basic-for-woocommerce/ # Version: <=13 # Tested on: Linux Description: proxyph ...