module
Wordpress Plainview Activity Monitor RCE
| Disclosed |
|---|
| Aug 26, 2018 |
Disclosed
Aug 26, 2018
Description
Plainview Activity Monitor Wordpress plugin is vulnerable to OS
command injection which allows an attacker to remotely execute
commands on underlying system. Application passes unsafe user supplied
data to ip parameter into activities_overview.php.
Privileges are required in order to exploit this vulnerability.
Vulnerable plugin version: 20161228 and possibly prior
Fixed plugin version: 20180826
command injection which allows an attacker to remotely execute
commands on underlying system. Application passes unsafe user supplied
data to ip parameter into activities_overview.php.
Privileges are required in order to exploit this vulnerability.
Vulnerable plugin version: 20161228 and possibly prior
Fixed plugin version: 20180826
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.