WordPress H5VP Plugin - Full Path Disclosure
The WordPress H5VP video plugin diclosed full server paths in stack traces when processing video requests.
html5_video_playerPoC 已收录
CVSS—
共找到 3 条公开漏洞记录
The WordPress H5VP video plugin diclosed full server paths in stack traces when processing video requests.
The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
WordPress HTML5 Video Player plugin is vulnerable to SQL injection. An unauthenticated attacker can exploit this vulnerability to perform SQL injection attacks.