Summary
The AllWebMenus plug-in for WordPress is prone to a remote file- include vulnerability because it fails to sufficiently sanitize user- supplied input.
Exploiting this issue could allow an attacker to compromise the application and the underlying system
other attacks are also
possible.
AllWebMenus 1.1.3 is vulnerable
other versions may also be affected.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2011-3981 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- AIOCP 'cp_html2xhtmlbasic.php' Remote File Inclusion Vulnerability
- Atlassian JIRA Privilege Escalation and Multiple Cross Site Scripting Vulnerabilities
- AlienVault OSSIM 'date_from' Parameter Multiple SQL Injection Vulnerabilities
- ALCASAR Remote Code Execution Vulnerability
- Apache Archiva Multiple Remote Command Execution Vulnerabilities