Extension WordPress
Vulnérabilités iMember360is
Cette page rassemble les failles publiées pour iMember360is, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de iMember360is
5 fiches
iMember360is 3.8.012 – 3.9.001 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) decrypt or (2) encrypt parameter.
[3.8.012, 3.9.002)
3.9.002
14/05/2014
iMember360 < 3.9.001 – Missing Authorization and Sensitive Data Exposure
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the i4w_dbinfo parameter.
[*, 3.9.001)
3.9.001
28/04/2014
iMember360 3.8.012 – 3.9.001 – Missing Authorization
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Email parameter and the API key in the…
[3.8.012, 3.9.001)
3.9.001
28/04/2014
iMember360 3.8.0.12 – 3.9.001 – Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote attackers to hijack the authentication of administrators for requests that with an unspecified impact via the i4w_trace parameter. NOTE: this can be…
[3.8.012, 3.9.001)
3.9.001
24/04/2014
iMember360 3.8.012 – 3.9.001 – Remote Code Execution
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to allow remote attackers to execute code. NOTE:…
3.8.012-3.9.001
3.9.002
24/04/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.