CVE-2011-3981: Code Injection
Published Oct 4, 2011
·Updated
PHP remote file inclusion vulnerability in actions.php in the Allwebmenus plugin 1.1.3 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.
Affected Software
2 affected components
Likno Allwebmenus Plugin=1.1.3
WordPress WordPress
Remediation
Event History
Oct 4, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
10:55 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-3981?
The severity of CVE-2011-3981 is rated as high with a score of 7.5.
2
How do I fix CVE-2011-3981?
To fix CVE-2011-3981, you should update to the latest version of the Allwebmenus plugin where a patch is available.
3
What type of vulnerability is CVE-2011-3981?
CVE-2011-3981 is a remote file inclusion vulnerability that allows arbitrary PHP code execution.
4
Which plugin is affected by CVE-2011-3981?
CVE-2011-3981 affects the Likno Allwebmenus plugin version 1.1.3 for WordPress.
5
Can attackers exploit CVE-2011-3981 without authentication?
Yes, attackers can exploit CVE-2011-3981 without authentication due to the nature of the vulnerability.