VYPR

Wordtube

by Ruben Boelinger

CVEs (2)

  • CVE-2007-2482May 3, 2007
    risk 0.05cvss epss 0.28

    Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the wpPATH parameter.

  • CVE-2007-2481May 3, 2007
    risk 0.03cvss epss 0.04

    PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.