7.5
CVE-2015-9415
- EPSS 15.53%
- Veröffentlicht 26.09.2019 00:15:10
- Zuletzt bearbeitet 21.11.2024 02:40:34
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
BJ Lazy Load < 1.0 - Remote File Inclusion via TimThumb
The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.
Mögliche Gegenmaßnahme
BJ Lazy Load: Update to version 1.0, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
BJ Lazy Load
Version
0.7.5
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Angrycreative ≫ Bj Lazy Load SwPlatformwordpress Version < 1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 15.53% | 0.944 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.