WordPress RokBox <= 2.13 - Arbitrary File Upload
critical
The WordPress RokBox plugin is vulnerable to arbitrary file uploads due to missing file type validation in the 'src' parameter in the 'thumb.php' file in versions up to, and including, 2.13. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remot...
- CVSS:
- 9.8
- Affected:
- up to 2.13
- Fix:
- No patched version reported
- Disclosed:
- Dec 17, 2012
WordPress RokBox <= 2.13 - Content Spoofing
critical
The WordPress RokBox plugin is vulnerable to Content Spoofing via the 'file', 'config', and 'abouttext' parameters in the 'thumb.php' and 'jwplayer.swf' files in versions up to, and including, 2.13. This makes it possible for unauthenticated attackers to spoof files from other domains.
- CVSS:
- 9.1
- Affected:
- up to 2.13
- Fix:
- No patched version reported
- Disclosed:
- Dec 17, 2012
WordPress RokBox <= 2.13 - Full Path Disclosure
high
The WordPress RokBox plugin is vulnerable to Full Path Disclosure in versions up to, and including, 2.13 via the 'rokbox.php' and 'thumb.php' files. This can allow unauthenticated attackers to extract full paths to otherwise restricted files.
- CVSS:
- 7.5
- Affected:
- up to 2.13
- Fix:
- No patched version reported
- Disclosed:
- Dec 17, 2012
WordPress RokBox <= 2.13 - Denial of Service
high
The WordPress RokBox plugin is vulnerable to Denial of Service via the 'src' parameter in the 'thumb.php' file in versions up to, and including, 2.13. This makes it possible for unauthenticated attackers to slow the response time of the vulnerable service to an unusable speed and/or completely deny it.
- CVSS:
- 7.5
- Affected:
- up to 2.13
- Fix:
- No patched version reported
- Disclosed:
- Dec 17, 2012
WordPress RokBox <= 2.13 - Cross-Site Scripting
medium
The WordPress RokBox plugin is vulnerable to Cross-Site Scripting via the 'src' and 'abouttext' parameters in the 'thumb.php' and 'jwplayer.swf' files in versions up to, and including, 2.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...
- CVSS:
- 6.1
- Affected:
- up to 2.13
- Fix:
- No patched version reported
- Disclosed:
- Dec 17, 2012
WordPress RokBox <= 2.13 - Sensitive Data Disclosure
medium
The WordPress RokBox plugin is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.13 via the error_log. This can allow unauthenticated attackers to extract sensitive data including error logs which may disclose full paths.
- CVSS:
- 5.3
- Affected:
- up to 2.13
- Fix:
- No patched version reported
- Disclosed:
- Dec 17, 2012
WordPress RokBox <= 2.13 - Abuse of Functionality
medium
The WordPress RokBox plugin is vulnerable to Abuse of Functionality via the 'src' parameter in the 'thumb.php' file in versions up to, and including, 2.13. This makes it possible for unauthenticated attackers to use implemented functions for unintended/malicious reasons.
- CVSS:
- 5.3
- Affected:
- up to 2.13
- Fix:
- No patched version reported
- Disclosed:
- Dec 17, 2012
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database