Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2015-4615

Disclosure Date: February 15, 2019 (last updated November 27, 2024)
Vulnerability in Easy2map-photos WordPress Plugin v1.09 allows SQL Injection via unsanitized mapTemplateName, mapName, mapSettingsXML, parentCSSXML, photoCSSXML, mapCSSXML, mapHTML,mapID variables
0
Attacker Value
Unknown

CVE-2015-4617

Disclosure Date: February 15, 2019 (last updated November 27, 2024)
Vulnerability in Easy2map-photos WordPress Plugin v1.09 MapPinImageUpload.php and MapPinIconSave.php allows path traversal when specifying file names creating files outside of the upload directory.
0
Attacker Value
Unknown

CVE-2015-7669

Disclosure Date: December 27, 2017 (last updated November 26, 2024)
Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfile parameter related to "upload file functionality."
0
Attacker Value
Unknown

CVE-2015-7668

Disclosure Date: December 27, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.3.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter.
0
Attacker Value
Unknown

CVE-2015-4616

Disclosure Date: July 08, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.2.5 for WordPress allows remote attackers to create arbitrary files via a .. (dot dot) in the map_id parameter.
0
Attacker Value
Unknown

CVE-2015-4614

Disclosure Date: July 08, 2015 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the mapName parameter in an e2m_img_save_map_name action to wp-admin/admin-ajax.php and other unspecified vectors.
0