PHP Remote File Inclusion Vulnerability in Sniplets Plugin for WordPress
CVE-2008-1059

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
28 February 2008

Summary

The Sniplets plugin for WordPress versions 1.1.2 and 1.2.2 contains a PHP remote file inclusion vulnerability found in the modules/syntax_highlight.php file. This flaw allows remote attackers to execute arbitrary PHP code by manipulating the 'libpath' parameter within the request URL. Successful exploitation of this vulnerability could lead to unauthorized access and control over affected WordPress installations, putting sensitive data and site integrity at risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.