icon

We found results for “

CVE-2016-10991

Good to know:

icon

Date: September 17, 2019

The imdb-widget plugin before 1.0.9 for WordPress has Local File Inclusion.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Input Validation

CWE-20

Top Fix

icon

Upgrade Version

Upgrade to version dmk/mktools - 3.0.3;dmk/mktools - dev-dependabot/composer/Resources/Private/PHP/erusev/parsedown-1.7.2;dmk/mktools - dev-legacy-3.0;usama/blogpack - no_fix;arckinteractive/elgg_hybridauth - 1.3.2;arckinteractive/elgg_hybridauth - dev-1.8_backport;arckinteractive/elgg_hybridauth - dev-master;medz/thinksns-4 - 4.1.520;medz/thinksns-4 - 4.1.862;medz/thinksns-4 - 4.1.648;drupal/core-assertion - 8.1.0;drupal/core-assertion - 8.0.0-beta6;vufind/vufind - dev-legacy/bootstrap;vufind/vufind - v1.28.0;vufind/vufind - dev-release-3.0;tzi/svg-tool - no_fix;controleonline/speed-up-essentials - no_fix;controleonline/speed-up-essentials - v1.0.0;wildzero/image-upload - no_fix;medz/thinksns - 4.1.520;medz/thinksns - 4.1.862;medz/thinksns - 4.1.648;elucidate/cache - no_fix;getdkan/open_data_schema_map - 7.x-2.5;getdkan/open_data_schema_map - 7.x-1.13-beta1;getdkan/open_data_schema_map - no_fix;getdkan/open_data_schema_map - 7.x-2.1;carlosocarvalho/coci - no_fix;purepanel/dashboard-module - v1.0.2;boboldehampsink/cronjob - 0.1.1;anomaly/addons-module - v1.0.3;reelworx/rx-shariff - 4.0.0;drupal/drupal - 8.0.0-rc2;drupal/drupal - 8.0.0-rc4;drupal/drupal - 8.0.0-beta2;digitalunited/hausrock - 1.3.33;lvincesl/html_template - 1.0.2;ycms/college - no_fix;astridx/joomla-cms - 3.5.0-beta;learnosity/learnosity-qti - v0.2.0-rc.1;learnosity/learnosity-qti - v0.3.0-rc.2;learnosity/learnosity-qti - v0.4.0-rc.3;learnosity/learnosity-qti - v0.5.0;learnosity/learnosity-qti - v0.1.0-rc.3;basdog22/anastasia - no_fix;howtomakeaturn/live-reload-kid - no_fix;quallsbenson/illuminate - v0.1.0;quallsbenson/illuminate - no_fix;mraiur/google - v0.1.1;cmtz/bc-migrator - no_fix;ground-hogs/nabu - no_fix;ground-hogs/nabu - v0.0.4;lucbu/angkor-cms - first;lucbu/angkor-cms - no_fix;swith/framework - v2.2;drupal/core-render - 8.1.0;drupal/core-render - 8.0.0-beta6;destinydriven/cakephp3-highcharts - no_fix;deeparya/zfiles - no_fix;ycms/theme-evo - 添加主题配置权限给admin用户;jayzeng/virustotalapi - dev-guzzle_fix;maxwen/yii2-ckeditor-widget - 1.0.2;seer/seer - no_fix;o-log/php-bt - 1;tazzy/helpers - dev-master;juniorgol/hello-world - 0.3-dev;juniorgol/hello-world - no_fix;juniorgol/hello-world - 0.5.x;milo/web-project - v1.5;reliv/rcm-dynamic-navigation - 0.1.2;anomaly/appearance-module - v1.0.5;fileio/dag-client - no_fix;code-fury/laravel-captcha - no_fix;code-fury/laravel-captcha - v.0.0.3;visiosoft/preferences-module - v1.0.5;lramos1994/wp-api-jwt-auth - 1.2.1;sti-vcx/sti-framework - no_fix;jtaurus/autoinstantiator - no_fix;arckinteractive/elgg_stormpath - no_fix;asposecells/aspose_cells_java_for_php - no_fix;decidir2/php-sdk - V1.0.0;decidir2/php-sdk - no_fix;drupal/core-file-cache - 8.1.0;jeroendesloovere/geolocation-bundle - no_fix;jeroendesloovere/geolocation-bundle - 0.0.2;anomaly/dashboard-module - v1.0.2;rmoore/phppdu - dev-master;rmoore/phppdu - v1.2.11;fozbek/uri-resolver - v2.3.34;fozbek/uri-resolver - v2.7.6;fozbek/uri-resolver - v2.6.0-BETA1;vijaycs85/coverage-report - 8.0.0-beta2;vijaycs85/coverage-report - 8.0.0-rc4;azi/raskoh - 1.3.1;azi/raskoh - no_fix;masterflash-ru/ckfinder - 1.0.4;sun/session - no_fix;usama/gallery-pack - no_fix;linhecheng/cmlphp - v2.3.34;linhecheng/cmlphp - v2.5.0;linhecheng/cmlphp - v2.7.5;linhecheng/cmlphp - 2.7.x-dev;linhecheng/cmlphp - v2.6.0;symfony/symfony - v2.6.0;symfony/symfony - v2.6.0-BETA1;symfony/symfony - 2.7.x-dev;symfony/symfony - v2.3.34;symfony/symfony - v2.5.0;symfony/symfony - v2.7.6;tijisoft/mobileception - no_fix;monkblog/theme-manager - no_fix;monkblog/theme-manager - 1.1.x-dev;cymapgt/usercredential - 1.2.3;visiosoft/files-module - v1.0.7;maiorano84/bolt-shortcodes - no_fix;webflo/drupal - no_fix;carlosocarvalho/router - no_fix;weicms/doc - no_fix;hypejunction/hypescraper - 4.1.0;payway-ar/php-sdk-venta-online - dev-feature/FPP11-3363-3DS-payment;payway-ar/php-sdk-venta-online - no_fix;jsartisan/shopkart-laravel - no_fix;visiosoft/posts-module - v1.0.23;flijten/blog - no_fix;fetch404/fetch404 - no_fix;joshdifabio/composer - no_fix;genix/cms - v0.0.8;boboldehampsink/pushnotifications - dev-feature/wns;boboldehampsink/pushnotifications - 0.3.2;visiosoft/navigation-module - v1.0.5;venca-x/web-project - v1.5;anomaly/search-module - v2.0.7;anomaly/search-module - 3.0.x-dev;anomaly/search-module - v2.0.1;sun/filesystem - no_fix;cehojac/antonella-framework-for-wp - dev-develop;cehojac/antonella-framework-for-wp - dev-release/1.5;mraiur/youtube-mp3-helper - no_fix;anomaly/files-module - v1.0.7;josephniel/project-base - no_fix;ikanc/binlist - no_fix;fisharebest/webtrees - 1.7.x-dev;fisharebest/webtrees - 1.7.2;devshop/devmaster - 1.x-dev;devshop/devmaster - 1.5.0-rc1;experience/smartdown - 2.0.0;ycms/main - no_fix;omise/omise-magento - v1.8;omise/omise-magento - v1.9.0.4;nomantufail/helloworld - no_fix;sun/alien - v1.7;symfony/dom-crawler - 2.7.x-dev;symfony/dom-crawler - v2.6.0-BETA1;symfony/dom-crawler - v2.6.0;symfony/dom-crawler - v2.3.34;symfony/dom-crawler - v2.7.6;symfony/dom-crawler - v2.5.0;omarelgabry/miniphp - v2.0;thepost/the-post - v0.2;facundocapua/php-sdk - no_fix;enchance/helpers - v0.2.5;vsalvans/twig-translation - no_fix;stalk/core - no_fix;sandpkg/mypkg - no_fix;rivomanana/rvslimbase - no_fix;dev-temp/plugins - no_fix;dung/helloworld - no_fix;rcm/dynamic-navigation - 0.1.2;anomaly/configuration-module - v1.0.4;drupal/core-http-foundation - 8.1.0;drupal/core-http-foundation - 8.0.0-beta6;bonweb/laradmin - no_fix;sammet/gestion-colecciones - no_fix;ycms/module-main - no_fix;siwymilek/guests - no_fix;abbassi/infographics - no_fix;yanpengquan/socketframework - no_fix;quallsbenson/repository - v.0.1.01;ycms/framework - v5.1.0;icurdinj/config - no_fix;sanatorium/shop - 0.2.0;shogochiai/php-zmq - 0.1.0;pragmaticlinux/laravel - no_fix;teamv/php-sdk2 - no_fix;teamv/php-sdk2 - dev-feature/FPP11-3363-3DS-payment;freesoftwarefactory/cruge - no_fix;sarfraznawaz2005/bloggercms - no_fix;sdkconnector/ppconectorsdk - no_fix;elgg/elgg - 2.2.x-dev;mi-squared/mi-framework - no_fix;useful-web/yii2-leaflet-search - no_fix;n1n7axiii/gallery - no_fix;anomaly/pages-module - v1.0.28;visiosoft/pages-module - v1.0.28;pragmaticlinux/yii-basic - no_fix;jono/view - no_fix;boboldehampsink/youtube - 0.1.5;kingjan1999/vertretungsplan - no_fix;jono/router - no_fix;vint3/remove-projects-in-divi - 1.1.1;dolibarr/dolibarr - 3.9.0-rc;mothership-ec/composer - no_fix;mothership-ec/composer - 1.0.0-alpha1;anomaly/navigation-module - v1.0.5;clagiordano/weblibs-mvc - dev-feature/refactor;aazeev/dota2stats - no_fix;safaricco/admfw - no_fix;michaeldrennen/laravel-bugify - no_fix;anvarco/sdkpayu - no_fix;pela-framework/pela-framework - no_fix;quallsbenson/utility-object - no_fix;academies-trust/less-framework - v0.2.41;academies-trust/less-framework - v0.2.4;academies-trust/less-framework - v0.1;leiqianghua/lqh1 - no_fix;ldynia/core - no_fix;cuminlo/filecache - no_fix;anomaly/installer-module - v1.0.7;bnowack/scss-watcher - no_fix;bnowack/scss-watcher - 0.1.0;civicrm/civicrm-packages - 4.4.1;civicrm/civicrm-packages - 4.5.0;dmk/t3rest - v1.1.2;anomaly/preferences-module - v1.0.5;pixidos/web-project - v1.5;shadywallas/arpuplussms - no_fix;purepanel/files-module - v1.0.7;sunfoxcz/nette-project - v1.5;cymapgt/spreadsheetprocessor - no_fix;drupal/core-dependency-injection - 8.0.0-beta15;drupal/core-dependency-injection - 8.0.0-rc1;ibericode/boxzilla-wp - 2.1.4;ibericode/boxzilla-wp - dev-dependabot/npm_and_yarn/copy-props-2.0.5;ntoklo/ntokloapi-php - no_fix;chlalbuquerque/yii2-kitdevelop - no_fix;peytz-wordpress/pco-kint - 1.0.10;listo4ek/laravel-metronic - 0.3;wahid/middleware - no_fix;andreribas/muvuca - no_fix;markitosgv/bowling-kata - v1.0;saurabhaec/zf2-php-resque - no_fix;xww1112/helloword - no_fix;ventureoak/vox - 0.3.0;nerds-and-company/craft-sentry - 1.1.2;dannyvankooten/mailchimp-for-wordpress - 2.3.10;drupal/core - 8.0.0-beta16;drupal/core - 8.0.0-rc1;openclassify/posts-module - v1.0.23;idmkr/laravel-blade-fix - no_fix;ibericode/wp-knowledge-base - dev-master;weicms/laravel - no_fix;lucadamo-dev/decidir-sdk-php - no_fix;jackkum/phppdu - no_fix;jackkum/phppdu - v1.0;birgir/combined-query - 1.0.1;lambda-platform/laravel - v0.0.7;erkenes/heise-shariff - 1.5.1;hostjams/dispose-email - no_fix;nekojira/wp-php-console - 1.4.0;ivanbay/rosecomarketingventure - no_fix;heise/shariff - 1.5.1;sarfraznawaz2005/phexecute - dev-master;boboldehampsink/rollbar - 1.4.0;noercholis/pacms - no_fix;anomaly/posts-module - v1.0.23;reneschmidt/rspassword - no_fix;slub/slub-find-extend - 1.x-dev;barrelstrength/sprout-fields - 3.0.0;sun/task - no_fix;nagy/permissions-handler - 2.0;sun/flash - no_fix;alex-moreno/stubby4php - no_fix;nette/web-project - v1.5;brunowerneck/buscacep - 0.1.1;designplug/repository - v0.1.0;matricks/yii2-blitz - no_fix;willpsng/laravel-rid - 1.1;purepanel/configuration-module - v1.0.4;anomaly/blog-module - v1.0.23;adkgamers/bfadmincp - v2.0.1;my-oos/my-oos - v2.0.60;lvinceslas/htmltemplate - 1.0.2;redactivemedia/redactive-drupal8-platform - 8.0.0;ratno/belajar - no_fix;eold/yii2-apidoc-generator - no_fix

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): NONE
Availability (A): NONE

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): LOW
Authentication (AU): NONE
Confidentiality (C): PARTIAL
Integrity (I): NONE
Availability (A): NONE
Additional information:

Do you need more information?

Contact Us