WordPress Sell Download plugin version 1.0.16 suffers from a local file disclosure vulnerability.
6ff16b263dc80eedb9844cca7e1581b90e3a21d7503569de87d0ad55b2ba2797
WordPress TheCartPress plugin version 1.4.7 suffers from code execution and local file disclosure vulnerabilities.
154e643451779441be905f0e36b20623d19f59932732426b2c51832ab87df6db
WordPress Advanced Uploader plugin version 2.10 suffers from a remote shell upload vulnerability.
c84ffbb5a2da901b10a9231b2d47a0cd53878657e2c02246099c1a67a27b4476
This Metasploit module exploits an arbitrary file upload in the WordPress InBoundio Marketing plugin version 2.0. It allows you to upload arbitrary php files and get remote code execution. This Metasploit module has been tested successfully on WordPress InBoundio Marketing 2.0.3 with Wordpress 4.1.3 on Ubuntu 14.04 Server.
114356930e9c145630aeafa00184f2b3246d456a0167279e09bbfc184d6c975e
WordPress InBoundio Marketing plugin suffers from a remote shell upload vulnerability.
7940c1bcc1be530b886d2e8945d3daedf9179235dd53a629eff265af18c5f93c
WordPress MP3-Jplayer plugin version 2.3 suffers from a local file disclosure vulnerability.
0029d652e04d0be61d22db15d7a2fc2394e42ed9f13fde78fd7c9d9c0ad7c71d
Ckeditor version 4.4.7.x suffers from cross site scripting and remote shell upload vulnerabilities.
ff9f0475f02a2da2c698414df7fb0c688da73c1d1cf63ce8051b290f339e9813
WordPress WP-E-Commerce plugin version 3.8.9.5 suffers from local file inclusion, cross site scripting, cross site request forgery, file upload, and code execution vulnerabilities.
edba02aaa935d1d5f1e5623a4cb8bd063c56bc9ce671b002045fc66a328f645e
ZenPhoto version 1.4.4 suffers from path disclosure and remote SQL injection vulnerabilities.
470b780f56364cf82baed219380d3c27f21f8fb21b23a8c4496379d034e09f39
Maian Uploader version 4.0 suffers from cross site scripting, path disclosure, and remote SQL injection vulnerabilities.
d7a6ac8750185aaa81fb74d38aa9efff8e895ffa86f098558cdede3976bf83ff
osCmax e-Commerce version 2.5.3 suffers from cross site scripting and remote shell upload vulnerabilities.
98860934dd3a5b358b5cfd2a7330aad09c77227902a99dc4747915d3109cca00
RedAxScript version 1.1 suffers from multiple remote blind SQL injection vulnerabilities.
6b8f36199e8357cbfbdbc3b62976f84893ecd710c4ba586c66a459357a175c5e
NeoBill version 0.9-alpha eCommerce suffers from local file inclusion, remote command execution, and remote SQL injection vulnerabilities.
a6206ac0375cd11d4b17033ae59e79dc8053b70ceca001d1b28de6d6ca4d3332
TinyMCE version 3.2.7 suffers from SQL injection bypass and remote shell upload vulnerabilities.
da157be90c213de25691605033cf76109eb9523b6e6b3a241e799fbda9a598d4
OmegaBB versions 0.9.3 and below suffer from cross site request forgery and shell upload vulnerabilities.
f74fb7624092fe259119d512c1bde7090aad824aa0c23b1d507af0a630296a3b
Matterdaddy Market version 1.4.2 and below suffers from cross site request forgery and arbitrary file upload vulnerabilities.
0b8140e53c7c0f1f92e8675c79e10a58397a4335cc65b525b3ae336d8c75f408
SWFUpload suffers from cross site scripting, cross site request forgery, and object injection vulnerabilities.
88f9aac6098d0e3258845fe60905a4307536ba1d86078b4b59c2122b60d3ea28
EasyPHP Webserver suffers from a remote shell injection vulnerability.
8023e28ae85a6fa58ded8c8f3b1d3e28c39c30d6050dc359007394c1db06a0b3
224 bytes small Linux/x86 command download and execute shellcode.
b2ab122f0b624df2a06e2a514763a338a1196329e54bf5d63bb09d88b6e87f48
KindEditor version 4.1.5 suffers from a remote shell upload vulnerability.
d88c733d219132a2b1ee32a692f47acc95782683a3c055cf97d79c82150148cb
PHPBoost version 4.0 suffers from shell upload and information disclosure vulnerabilities.
57a0ed69df2dfe6a08556e979aa44517e786e8aafe00b57724d89f4f48485e75
Joomla GarysCookBook version 3.0.x suffers from a remote shell upload vulnerability.
126ffd8e875a7e1ec877fe617947622987f1cd173737ab8cf94795ba740a3f55
phpLiteAdmin versions 1.8.x and 1.9.x suffer from remote SQL injection and path disclosure vulnerabilities.
0040b2134dfa5935dcd304cb28a4d32278bb7672c063c3ca3bef062b3e1fa1a7
Nibbleblog version 3.4 suffers from path disclosure and shell upload vulnerabilities.
4a9155a4b7e5e0064087bb554e20c312f71b9305a572fb44142bbcdc6c4fc503
Drupal versions 6.x through 7.18 suffer from getimagesize() path and information disclosure vulnerabilities.
34d3057e774046cc520c1382be17b13f86fced4961308ef915eed34cc0f4d906