Record summary

CVE-2015-5065 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before 1.4 for WordPress allows remote attackers to read arbitrary files via a full pathname in the requrl parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 5, 2015 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Paypal Currency Converter Basic For WooCommerce - File ReadExploitDB exploitby Kuroi'SHNot analyzed1 file
ExploitDB

PoC details

References

6