packetstormsecurity.com
http://packetstormsecurity.com/files/132278/WordPress-Paypal-Currency-Converter-Basic-For-Woocommerce-1.3-File-Read.html CVE-2015-5065
intelligent-it paypal_currency_converter_basic_for_woocommerce Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2015-5065 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before 1.4 for WordPress allows remote attackers to read arbitrary files via a full pathname in the requrl parameter.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 5, 2015 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
paypal_currency_converter_basic_for_woocommerceBrowse intelligent-it / paypal_currency_converter_basic_for_woocommerce | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Paypal Currency Converter Basic For WooCommerce - File ReadExploitDB exploitby Kuroi'SHNot analyzed1 file
References
675416vdb entry
http://www.securityfocus.com/bid/75416 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-5065 plugins.trac.wordpress.orgConfirmation
https://plugins.trac.wordpress.org/changeset/1179092/paypal-currency-converter-basic-for-woocommerce wordpress.orgConfirmation
https://wordpress.org/plugins/paypal-currency-converter-basic-for-woocommerce/changelog 37253exploit
https://www.exploit-db.com/exploits/37253