94495vdb entry
http://www.securityfocus.com/bid/94495 CVE-2015-1000012
HIGHNuclei
WordPress MyPixs <=0.3 - Local File Inclusion
Record summary
CVE-2015-1000012 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHWordPress MyPixs <=0.3 - Local File InclusionCVSS 7.5
WordPress MyPixs 0.3 and prior contains a local file inclusion vulnerability.
Impact
An attacker can exploit this vulnerability to read sensitive files, execute arbitrary code, or gain unauthorized access to the server.
Remediation
Update to the latest version of the MyPixs plugin (>=0.4) or apply the vendor-provided patch to fix the LFI vulnerability.
WeaknessesCWE-200
Authorsdaffainfo
Template tagscvecve2015wordpresswp-pluginlfiwpscanmypixs_projectvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:mypixs_project:mypixs:0.3:*:*:*:*:wordpress:*:*
Google: inurl:"/wp-content/plugins/mypixs"
https://wpscan.com/vulnerability/24b83ce5-e3b8-4262-b087-a2dfec014985 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1000012 http://www.vapidlabs.com/advisory.php?v=154 https://nvd.nist.gov/vuln/detail/CVE-2015-1000012 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3vapidlabs.com
http://www.vapidlabs.com/advisory.php?v=154 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-1000012