Описание
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2015-4133
- https://wordpress.org/plugins/reflex-gallery/changelog
- https://wpvulndb.com/vulnerabilities/7867
- https://www.exploit-db.com/exploits/36809
- http://osvdb.org/show/osvdb/88853
- http://packetstormsecurity.com/files/130845
- http://packetstormsecurity.com/files/131515
- http://www.securityfocus.com/bid/57100
EPSS
CVE ID
Связанные уязвимости
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.
EPSS