Wordpress Sniplets Plugin vulnerabilities
3 known vulnerabilities affecting wordpress/sniplets_plugin.
Total CVEs
3
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2008-1060P2HIGHCVSS 7.5PoCv1.1.2v1.2.22008-02-28
CVE-2008-1060 [HIGH] CWE-94 CVE-2008-1060: Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordP
Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via the text parameter.
nvd
CVE-2008-1059P3HIGHCVSS 7.5PoCv1.1.2v1.2.22008-02-28
CVE-2008-1059 [HIGH] CWE-94 CVE-2008-1059: PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.
PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter.
nvd
CVE-2008-1061P4MEDIUMCVSS 4.3PoCv1.1.2v1.2.22008-02-28
CVE-2008-1061 [MEDIUM] CWE-79 CVE-2008-1061: Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordP
Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to (a) warning.php, (b) notice.php, and (c) inset.php in view/sniplets/, and possibly (d) modules/execute.php; the (2) url parameter to (e) view/admin/submenu.p
nvd