Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4m7w-g6rc-g3w7

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.

Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.

EPSS

Процентиль: 94%
0.13443
Средний

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 13 лет назад

Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.

EPSS

Процентиль: 94%
0.13443
Средний

Дефекты

CWE-20