File Manager Plugin 3.0.1 ka WordPress Kari ndiyam site laa request forgery

Wuro vulnerability wey an yi classify sey karshewa an gano shi a cikin File Manager Plugin 3.0.1 on WordPress. Gaskiya, $software_function na da matsala; idan ba a sani ba, to wata aiki ce da ba a sani ba, $software_library na cikin lissafi, $software_file na cikin fayil, $software_component na cikin sashi. Ngam manipulation shi Kari ndiyam site laa request forgery. CWE shidin ka a yi bayani matsala sai ya kai CWE-352. Gaskiya, laifi an fitar da shi 03/01/2017 ta David Vaartjes a matsayin Cross-Site Request Forgery in File Manager WordPress plugin a matsayin Mailinglist Post (Bugtraq). Advisory ɗin ana rabawa don saukewa a seclists.org. Wannan rauni ana sayar da shi da suna CVE-2017-20091. Ngam yiɗi ka a tuma ndiyam ka nder internet. Tekinikal bayani ba ga. Ba exploit ɗin da ake da shi. A sa'i, exploit might be approx. USD $0-$5k ndiyam. Á wúro a wondi feere. Kama 0-day, an ndiyam a wuro be $0-$5k. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.

3 Goyarwa · 41 Datenpunkte

FurɗeSúgá
03/01/2017 17:34
Gargadi 1/2
08/18/2020 09:21
Gargadi 2/2
06/19/2022 18:01
software_nameFile Manager PluginFile Manager PluginFile Manager Plugin
software_version3.0.13.0.13.0.1
software_platformWordPressWordPressWordPress
vulnerability_risk111
cvss2_vuldb_basescore4.34.34.3
cvss2_vuldb_tempscore4.14.14.1
cvss2_vuldb_avNNN
cvss2_vuldb_acMMM
cvss2_vuldb_auNNN
cvss2_vuldb_ciNNN
cvss2_vuldb_iiPPP
cvss2_vuldb_aiNNN
cvss3_meta_basescore4.34.34.3
cvss3_meta_tempscore4.24.24.2
cvss3_vuldb_basescore4.34.34.3
cvss3_vuldb_tempscore4.24.24.2
cvss3_vuldb_avNNN
cvss3_vuldb_acLLL
cvss3_vuldb_prNNN
cvss3_vuldb_uiRRR
cvss3_vuldb_sUUU
cvss3_vuldb_cNNN
cvss3_vuldb_iLLL
cvss3_vuldb_aNNN
advisory_date1488326400 (03/01/2017)1488326400 (03/01/2017)1488326400 (03/01/2017)
advisory_locationBugtraqBugtraqBugtraq
advisory_typeMailinglist PostMailinglist PostMailinglist Post
advisory_urlhttp://seclists.org/bugtraq/2017/Feb/57http://seclists.org/bugtraq/2017/Feb/57http://seclists.org/bugtraq/2017/Feb/57
advisory_identifierCross-Site Request Forgery in File Manager WordPress pluginCross-Site Request Forgery in File Manager WordPress pluginCross-Site Request Forgery in File Manager WordPress plugin
person_nameDavid VaartjesDavid VaartjesDavid Vaartjes
price_0day$0-$5k$0-$5k$0-$5k
cvss2_vuldb_eNDNDND
cvss2_vuldb_rlUUU
cvss2_vuldb_rcURURUR
cvss3_vuldb_eXXX
cvss3_vuldb_rlUUU
cvss3_vuldb_rcRRR
software_typeWordPress PluginWordPress Plugin
vulnerability_cweCWE-352 (Kari ndiyam site laa request forgery)CWE-352 (Kari ndiyam site laa request forgery)
source_cveCVE-2017-20091
cna_responsibleVulDB

Interested in the pricing of exploits?

See the underground prices here!