← Back

CVE-2012-1010

nvd nist
Published: Feb 7, 2012Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.

Affected (22)

1 product
Allwebmenus Plugin
Configuration A
22 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Likno
Up to 1.1.7
Version 1.0.10
Version 1.0.11
Version 1.0.12
Version 1.0.17
Version 1.0.18
Version 1.0.19
Version 1.0.1
Version 1.0.20
Version 1.0.21
Version 1.0.22
Version 1.0.23
Version 1.0.24
Version 1.0.3
Version 1.0.4
Version 1.0.9
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 1.1.6
Running on/withPlatform Versions
Wordpress
Wordpress
All versions

References (12)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.