Refine your search

2 vulnerabilities found for Shortcodes Ultimate by Vladimir Anokhin

CVE-2017-2245 (GCVE-0-2017-2245)
Vulnerability from cvelistv5
Published
2017-07-07 13:00
Modified
2024-08-05 13:48
Severity ?
CWE
  • Directory traversal
Summary
Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitrary files via unspecified vectors.
Impacted products
Vendor Product Version
Vladimir Anokhin Shortcodes Ultimate Version: prior to version 4.10.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-05T13:48:04.300Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://plugins.trac.wordpress.org/changeset/1684377/#file217"
          },
          {
            "name": "99495",
            "tags": [
              "vdb-entry",
              "x_refsource_BID",
              "x_transferred"
            ],
            "url": "http://www.securityfocus.com/bid/99495"
          },
          {
            "name": "JVN#63249051",
            "tags": [
              "third-party-advisory",
              "x_refsource_JVN",
              "x_transferred"
            ],
            "url": "https://jvn.jp/en/jp/JVN63249051/index.html"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://wordpress.org/plugins/shortcodes-ultimate/#developers"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Shortcodes Ultimate",
          "vendor": "Vladimir Anokhin",
          "versions": [
            {
              "status": "affected",
              "version": "prior to version 4.10.0"
            }
          ]
        }
      ],
      "datePublic": "2017-07-06T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitrary files via unspecified vectors."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Directory traversal",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2017-07-11T09:57:01.000Z",
        "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "shortName": "jpcert"
      },
      "references": [
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://plugins.trac.wordpress.org/changeset/1684377/#file217"
        },
        {
          "name": "99495",
          "tags": [
            "vdb-entry",
            "x_refsource_BID"
          ],
          "url": "http://www.securityfocus.com/bid/99495"
        },
        {
          "name": "JVN#63249051",
          "tags": [
            "third-party-advisory",
            "x_refsource_JVN"
          ],
          "url": "https://jvn.jp/en/jp/JVN63249051/index.html"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://wordpress.org/plugins/shortcodes-ultimate/#developers"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "vultures@jpcert.or.jp",
          "ID": "CVE-2017-2245",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "Shortcodes Ultimate",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "prior to version 4.10.0"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Vladimir Anokhin"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitrary files via unspecified vectors."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "Directory traversal"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://plugins.trac.wordpress.org/changeset/1684377/#file217",
              "refsource": "CONFIRM",
              "url": "https://plugins.trac.wordpress.org/changeset/1684377/#file217"
            },
            {
              "name": "99495",
              "refsource": "BID",
              "url": "http://www.securityfocus.com/bid/99495"
            },
            {
              "name": "JVN#63249051",
              "refsource": "JVN",
              "url": "https://jvn.jp/en/jp/JVN63249051/index.html"
            },
            {
              "name": "https://wordpress.org/plugins/shortcodes-ultimate/#developers",
              "refsource": "CONFIRM",
              "url": "https://wordpress.org/plugins/shortcodes-ultimate/#developers"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
    "assignerShortName": "jpcert",
    "cveId": "CVE-2017-2245",
    "datePublished": "2017-07-07T13:00:00.000Z",
    "dateReserved": "2016-12-01T00:00:00.000Z",
    "dateUpdated": "2024-08-05T13:48:04.300Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

jvndb-2017-000164
Vulnerability from jvndb
Published
2017-07-06 13:41
Modified
2018-02-07 11:52
Severity ?
Summary
WordPress plugin "Shortcodes Ultimate" vulnerable to directory traversal
Details
The WordPress plugin "Shortcodes Ultimate" contains a directory traversal vulnerability (CWE-22) in the Examples page. Chris Liu reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Impacted products
Show details on JVN DB website


{
  "@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000164.html",
  "dc:date": "2018-02-07T11:52+09:00",
  "dcterms:issued": "2017-07-06T13:41+09:00",
  "dcterms:modified": "2018-02-07T11:52+09:00",
  "description": "The WordPress plugin \"Shortcodes Ultimate\" contains a directory traversal vulnerability (CWE-22) in the Examples page.\r\n\r\nChris Liu reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
  "link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000164.html",
  "sec:cpe": {
    "#text": "cpe:/a:shortcodes_ultimate_project:shortcodes_ultimate",
    "@product": "Shortcodes Ultimate",
    "@vendor": "Vladimir Anokhin",
    "@version": "2.2"
  },
  "sec:cvss": [
    {
      "@score": "4.0",
      "@severity": "Medium",
      "@type": "Base",
      "@vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
      "@version": "2.0"
    },
    {
      "@score": "5.0",
      "@severity": "Medium",
      "@type": "Base",
      "@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
      "@version": "3.0"
    }
  ],
  "sec:identifier": "JVNDB-2017-000164",
  "sec:references": [
    {
      "#text": "https://jvn.jp/en/jp/JVN63249051/index.html",
      "@id": "JVN#63249051",
      "@source": "JVN"
    },
    {
      "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2245",
      "@id": "CVE-2017-2245",
      "@source": "CVE"
    },
    {
      "#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2245",
      "@id": "CVE-2017-2245",
      "@source": "NVD"
    },
    {
      "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
      "@id": "CWE-22",
      "@title": "Path Traversal(CWE-22)"
    }
  ],
  "title": "WordPress plugin \"Shortcodes Ultimate\" vulnerable to directory traversal"
}