Summary
The Annonces plug-in for WordPress is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user- supplied input.
Exploiting this issue could allow an attacker to compromise the application and the underlying system
other attacks are also
possible.
Annonces 1.2.0.0 is vulnerable
other versions may also be affected.
References
Severity
Classification
-
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities
- AbanteCart Multiple Cross-Site Scripting Vulnerabilities
- @Mail 'admin.php' Cross-Site Scripting Vulnerabilities
- Aardvark Topsites PHP 'index.php' Multiple Cross Site Scripting Vulnerabilities
- Alt-N WebAdmin Remote Source Code Information Disclosure Vulnerability
- A Really Simple Chat Multiple XSS Vulnerabilities