7.5

CVE-2012-0934

Exploit

PHP remote file inclusion vulnerability in ajax/savetag.php in the Theme Tuner plugin for WordPress before 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the tt-abspath parameter.

Data is provided by the National Vulnerability Database (NVD)
ZingiriTheme Tuner Plugin Version <= 0.7
   WordpressWordpress
ZingiriTheme Tuner Plugin Version0.1
   WordpressWordpress
ZingiriTheme Tuner Plugin Version0.2
   WordpressWordpress
ZingiriTheme Tuner Plugin Version0.3
   WordpressWordpress
ZingiriTheme Tuner Plugin Version0.4
   WordpressWordpress
ZingiriTheme Tuner Plugin Version0.6
   WordpressWordpress
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.51% 0.806
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.