Extension WordPress
Vulnérabilités Simple Ads Manager
Cette page rassemble les failles publiées pour Simple Ads Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Simple Ads Manager
7 fiches
Simple Ads Manager <= 2.9.8.125 – Unauthenticated PHP Objection Injection
The Simple Ads Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.9.8.125 via deserialization of untrusted input in the vulnerable function 'unserialize'. This allows unauthenticated attackers to inject a PHP…
[*, 2.10.0.130)
2.10.0.130
17/03/2017
SAM Pro (Free Edition) < 1.9.7.69 & Simple Ads Manager <= 2.10.0.130 & SAM Pro Lite < 1.9.0.53 – Local/Remote File Inclusion
The SAM Pro (Free Edition) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7.68 via the 'wap' parameter. This allows authenticated attackers to include and execute arbitrary files on the server,…
*-2.10.0.130
Non indiqué
10/10/2016
Simple Ads Manager <= 2.9.4.116 – SQL Injection
The Simple Ads Manager plugin for WordPress is vulnerable to unspecified SQL Injection via the ‘whereClause’ parameter in versions up to, and including, 2.9.4.116 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
[*, 2.9.5.118)
2.9.5.118
30/12/2015
Simple Ads Manager < 2.9.4.116 – Denial of Service
The Simple Ads Manager Plugin for WordPress is vulnerable to Denial of Service in versions before 2.9.4.116. This is due to an input validation flaw that allows an attacker to perform simple file system operations which can result…
[*, 2.9.4.116)
2.9.4.116
02/07/2015
Simple Ads Manager 2.5.94 & 2.5.96 – Information Disclosure
WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.
2.5.94, 2.5.96
2.5.97
02/04/2015
Simple Ads Manager < 2.7.97 – Multiple SQL Injections
Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in…
[*, 2.7.97)
2.7.97
02/04/2015
Simple Ads Manager <= 2.5.94 – Arbitrary File Upload
Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request…
*-2.5.94
2.5.96
01/04/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.