Sniplets < 1.2.3 - Remote Code Execution
critical
Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via the text parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Feb 26, 2008
CVE-2008-1060 on NVD →
Sniplets < 1.2.3 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to (a) warning.php, (b) notice.php, and (c) inset.php in view/sniplets/, and possibly (d) modules/execute.php; the (2) url par...
- CVSS:
- 6.1
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Feb 26, 2008
CVE-2008-1061 on NVD →
Sniplets < 1.2.3 - Remote File Inclusion
critical
PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Feb 25, 2008
CVE-2008-1059 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database