CVE-2015-7669

Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfile parameter related to "upload file functionality."
References
Link Resource
http://www.securityfocus.com/archive/1/536597/100/0/threaded Third Party Advisory VDB Entry
https://wordpress.org/plugins/easy2map/#developers Release Notes Third Party Advisory
https://wpvulndb.com/vulnerabilities/8206 Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/536597/100/0/threaded Third Party Advisory VDB Entry
https://wordpress.org/plugins/easy2map/#developers Release Notes Third Party Advisory
https://wpvulndb.com/vulnerabilities/8206 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:easy2map:easy2map:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 02:37

Type Values Removed Values Added
References () http://www.securityfocus.com/archive/1/536597/100/0/threaded - Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/536597/100/0/threaded - Third Party Advisory, VDB Entry
References () https://wordpress.org/plugins/easy2map/#developers - Release Notes, Third Party Advisory () https://wordpress.org/plugins/easy2map/#developers - Release Notes, Third Party Advisory
References () https://wpvulndb.com/vulnerabilities/8206 - Third Party Advisory, VDB Entry () https://wpvulndb.com/vulnerabilities/8206 - Third Party Advisory, VDB Entry

Information

Published : 2017-12-27 19:29

Updated : 2024-11-21 02:37


NVD link : CVE-2015-7669

Mitre link : CVE-2015-7669

CVE.ORG link : CVE-2015-7669


JSON object : View

Products Affected

easy2map

  • easy2map
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')