Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-2143


PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the fs_javascript parameter.


Published

2009-06-22T14:30:00.250

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application wordpress wordpress * No
Application firestats firestats ≤ 1.6.1 Yes
Application firestats firestats 0.9.0-beta Yes
Application firestats firestats 0.9.1-beta Yes
Application firestats firestats 0.9.2-beta Yes
Application firestats firestats 0.9.3-beta Yes
Application firestats firestats 0.9.4-beta Yes
Application firestats firestats 0.9.5-beta Yes
Application firestats firestats 0.9.6-beta Yes
Application firestats firestats 0.9.7-beta Yes
Application firestats firestats 0.9.8-beta Yes
Application firestats firestats 0.9.9 Yes
Application firestats firestats 1.0 Yes
Application firestats firestats 1.0.0 Yes
Application firestats firestats 1.0.1 Yes
Application firestats firestats 1.0.2 Yes
Application firestats firestats 1.0.2 Yes
Application firestats firestats 1.1.1 Yes
Application firestats firestats 1.1.2 Yes
Application firestats firestats 1.1.3 Yes
Application firestats firestats 1.1.3 Yes
Application firestats firestats 1.1.4 Yes
Application firestats firestats 1.1.5 Yes
Application firestats firestats 1.1.6 Yes
Application firestats firestats 1.1.7 Yes
Application firestats firestats 1.1.8 Yes
Application firestats firestats 1.2.0-beta Yes
Application firestats firestats 1.2.1 Yes
Application firestats firestats 1.2.2 Yes
Application firestats firestats 1.2.3 Yes
Application firestats firestats 1.2.4 Yes
Application firestats firestats 1.3.0-beta Yes
Application firestats firestats 1.3.1-beta Yes
Application firestats firestats 1.3.2-beta Yes
Application firestats firestats 1.3.3-beta Yes
Application firestats firestats 1.3.4 Yes
Application firestats firestats 1.3.5 Yes
Application firestats firestats 1.3.6 Yes
Application firestats firestats 1.4 Yes
Application firestats firestats 1.4.0-beta Yes
Application firestats firestats 1.4.1-beta Yes
Application firestats firestats 1.4.2-beta Yes
Application firestats firestats 1.4.3 Yes
Application firestats firestats 1.4.4 Yes
Application firestats firestats 1.5 Yes
Application firestats firestats 1.5.0-beta Yes
Application firestats firestats 1.5.1-beta Yes
Application firestats firestats 1.5.2-beta Yes
Application firestats firestats 1.5.3 Yes
Application firestats firestats 1.5.4 Yes
Application firestats firestats 1.5.5 Yes
Application firestats firestats 1.5.7 Yes
Application firestats firestats 1.5.8 Yes
Application firestats firestats 1.5.9 Yes
Application firestats firestats 1.5.10 Yes
Application firestats firestats 1.5.11 Yes
Application firestats firestats 1.5.12 Yes
Application firestats firestats 1.6 Yes
Application firestats firestats 1.6.0 Yes
Application firestats firestats 1.6.0 Yes
Application firestats firestats 1.6.0 Yes
Application firestats firestats 1.6.0 Yes
Application firestats firestats 1.6.0 Yes
Application firestats firestats 1.6.0 Yes
Application firestats firestats 1.6.0-beta1 Yes
Application firestats firestats 1.6.0-beta2 Yes
Application firestats firestats 1.6.1 Yes

References