Unrated severityNVD Advisory· Published May 3, 2007· Updated Apr 23, 2026
CVE-2007-2482
CVE-2007-2482
Description
Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the wpPATH parameter.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- secunia.com/advisories/25074nvdPatchVendor Advisory
- alexrabe.boelinger.comnvdExploitPatch
- www.securityfocus.com/bid/23737nvdExploitPatch
- advisories.echo.or.id/adv/adv81-K-159-2007.txtnvd
- osvdb.org/45168nvd
- securityreason.com/securityalert/2660nvd
- www.exploit-db.com/exploits/3825nvd
- www.securityfocus.com/archive/1/467362/100/0/threadednvd
- www.vupen.com/english/advisories/2007/1615nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/33996nvd
News mentions
0No linked articles in our index yet.