plugin

Sniplets Vulnerabilities

3 known security issues reported for the Sniplets WordPress plugin. Most recent disclosed Feb 26, 2008.

2 critical 1 medium

Running Sniplets on your site? Check whether your installed version is affected.

Scan your site free

Sniplets < 1.2.3 - Remote Code Execution

critical

Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via the text parameter.

CVSS:
9.8
Affected:
up to 1.2.3
Fixed in:
1.2.3
Disclosed:
Feb 26, 2008

CVE-2008-1060 on NVD →

Sniplets < 1.2.3 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to (a) warning.php, (b) notice.php, and (c) inset.php in view/sniplets/, and possibly (d) modules/execute.php; the (2) url par...

CVSS:
6.1
Affected:
up to 1.2.3
Fixed in:
1.2.3
Disclosed:
Feb 26, 2008

CVE-2008-1061 on NVD →

Sniplets < 1.2.3 - Remote File Inclusion

critical

PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter.

CVSS:
9.8
Affected:
up to 1.2.3
Fixed in:
1.2.3
Disclosed:
Feb 25, 2008

CVE-2008-1059 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database