2 results (0.001 seconds)

CVSS: 6.1EPSS: 2%CPEs: 1EXPL: 1

02 Sep 2016 — Reflected XSS in wordpress plugin infusionsoft v1.5.11 Vulnerabilidad de XSS reflejada en el plugin de wordpress infusionsoft v1.5.11 Reflected XSS in wordpress plugin infusionsoft v1.5.11 via the 'ContactId' parameter. • http://www.securityfocus.com/bid/93819 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 80%CPEs: 18EXPL: 6

26 Sep 2014 — The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php. El plugin Infusionsoft Gravity Forms 1.5.3 hasta 1.5.10 para WordPress no restringe debidamente el acceso, lo que permite a atacantes remotos subir ficheros arbitrarios y ejecutar código PHP arbitrario a través de una solicitud en utilities/code_generator.php. • https://packetstorm.news/files/id/128591 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-434: Unrestricted Upload of File with Dangerous Type •