CVE-2008-1060
Sniplets Plugin 1.1.2 and 1.2.2 - Remote Code Execution via Text Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1060. PoCs published by NBBN.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in WordPress Plugin Sniplets 1.1.2, including Remote File Inclusion (RFI), Cross-Site Scripting (XSS), and Remote Code Execution (RCE). The RFI and RCE vulnerabilities require 'Register Globals' to be enabled, while XSS can occur with or without it.
Description
Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via the text parameter.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in WordPress Plugin Sniplets 1.1.2, including Remote File Inclusion (RFI), Cross-Site Scripting (XSS), and Remote Code Execution (RCE). The RFI and RCE vulnerabilities require 'Register Globals' to be enabled, while XSS can occur with or without it.