CVE-2015-5065
50Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 16%
from disclosure to weapon0 days
Published on NVDJun 24
1st PoCJun 10
VulnCheck+103d
exploitation probability
16%top 3% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before 1.4 for WordPress allows remote attackers to read arbitrary files via a full pathname in the requrl parameter.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/132278/WordPress-Paypal-Currency-Converter-Basic-For-Woocommerce-1.3-File-Read.htmlunverifiedcve_referencewww.exploit-db.com/exploits/37253/unverifiedexploitdbwww.exploit-db.com/exploits/37253unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/132278/WordPress-Paypal-Currency-Converter-Basic-For-Woocommerce-1.3-File-Read.htmlhttps://plugins.trac.wordpress.org/changeset/1179092/paypal-currency-converter-basic-for-woocommercehttps://wordpress.org/plugins/paypal-currency-converter-basic-for-woocommerce/changelog/https://www.exploit-db.com/exploits/37253/http://www.securityfocus.com/bid/75416