VendorsLiknoallwebmenus_pluginall versions
Vulnerabilities

Likno Allwebmenus Plugin

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2011-3981
PHP remote file inclusion vulnerability in actions.php in the Allwebmenus plugin 1.1.3 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.
Published 2011-10-04 · Modified
7.51 PoCEPSS 0.101
CVE-2012-1011
actions.php in the AllWebMenus plugin 1.1.8 for WordPress allows remote attackers to bypass intended access restrictions to upload and execute arbitrary PHP code by setting the HTTP_REFERER to a certain value, then uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.
Published 2012-02-07 · Modified
7.51 PoCEPSS 0.090
CVE-2012-1010
Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.
Published 2012-02-07 · Modified
7.51 PoCEPSS 0.089