Vulnerabilities > Deliciousdays
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2015-01-08 | CVE-2014-9473 | File-Upload vulnerability in Deliciousdays Cformsii 14.7 Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file via a direct request to the file in the default upload directory. | 7.5 |
2010-11-03 | CVE-2010-3977 | Cross-Site Scripting vulnerability in Deliciousdays Cforms 11.5 Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters. | 4.3 |