S3 Bubble Amazon S3 HTML5 Video with Adverts <= 0.7 - Directory Traversal to Arbitrary File Access
high
The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
- CVSS:
- 7.5
- Affected:
- up to 0.7
- Fixed in:
- 0.8
- Disclosed:
- Jul 5, 2015
CVE-2015-9464 on NVD →
S3 Bubble Amazon S3 HTML5 Video with Adverts <= 2.0 - Arbitrary File Download
high
The S3 Bubble Amazon S3 HTML5 Video with Adverts plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.0. This is due to a lack of path restriction on the 'path' parameter in the download.php file. This makes it possible for unauthenticated attackers to download any file, inc...
- CVSS:
- 7.5
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 7, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database