History Collection [history-collection] <= 1.1.1 (unfixed + closed)
unknown
[en] The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.
- Affected:
- up to 1.1.1
- Fix:
- No patched version reported
- Disclosed:
- Oct 10, 2019
CVE-2015-9470 on NVD →
History Collection <=1.1.1 - Arbitrary File Download
high
The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.
- CVSS:
- 7.5
- Affected:
- up to 1.1.1
- Fix:
- No patched version reported
- Disclosed:
- Oct 6, 2015
CVE-2015-9470 on NVD →
History Collection [history-collection] < 1.1.2 (closed)
unknown
History Collection plugin is prone to an arbitrary file download vulnerability. "download.php" is not filtering the "get" input and the file can be downloaded because of this "get" input value.
Update the plugin.
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.2
- Disclosed:
- Jun 10, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database