Vulnerabilities
Vulnerable Software
Easy2map:  Security Vulnerabilities
Vulnerability in Easy2map-photos WordPress Plugin v1.09 allows SQL Injection via unsanitized mapTemplateName, mapName, mapSettingsXML, parentCSSXML, photoCSSXML, mapCSSXML, mapHTML,mapID variables
CVSS Score
9.8
EPSS Score
0.008
Published
2019-02-15
Vulnerability in Easy2map-photos WordPress Plugin v1.09 MapPinImageUpload.php and MapPinIconSave.php allows path traversal when specifying file names creating files outside of the upload directory.
CVSS Score
7.5
EPSS Score
0.004
Published
2019-02-15
Cross-site scripting (XSS) vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.3.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter.
CVSS Score
6.1
EPSS Score
0.001
Published
2017-12-27
Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfile parameter related to "upload file functionality."
CVSS Score
9.8
EPSS Score
0.036
Published
2017-12-27


Contact Us

Shodan ® - All rights reserved