Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-35hv-q2xv-q24x

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the upfile parameter, then accessing it via a direct request to the file in wp-content/plugins/downloads-manager/upload/.

Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the upfile parameter, then accessing it via a direct request to the file in wp-content/plugins/downloads-manager/upload/.

EPSS

Процентиль: 91%
0.06341
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 17 лет назад

Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the upfile parameter, then accessing it via a direct request to the file in wp-content/plugins/downloads-manager/upload/.

EPSS

Процентиль: 91%
0.06341
Низкий

Дефекты

CWE-20