vendor:
IMDb Profile Widget
by:
CrashBandicot @DosPerl
7,5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: IMDb Profile Widget
Affected Version From: 1.0.8
Affected Version To: 1.0.8
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:wordpress_plugin:imdb_widget
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: MSWin32
2016
WordPress Plugin IMDb Profile Widget – Local File Inclusion
The Wordpress Plugin IMDb Profile Widget is vulnerable to Local File Inclusion. An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable pic.php file with the URL parameter set to a malicious file. This will allow the attacker to read the contents of the malicious file.
Mitigation:
The vendor should update the plugin to the latest version and ensure that user input is properly sanitized.