wordTube <= 1.43 - Remote File Inclusion
critical
PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.43
- Fixed in:
- 1.44
- Disclosed:
- May 1, 2007
CVE-2007-2481 on NVD →
wordTube <= 1.43 - Directory Traversal and File Inclusion
critical
The wordTube plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.43 via the 'wpPATH' parameter found in the wordtube-button.php file. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information. This can al...
- CVSS:
- 9.8
- Affected:
- up to 1.43
- Fixed in:
- 1.44
- Disclosed:
- May 1, 2007
CVE-2007-2482 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database