Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxg6-f773-g2f7

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

jQuery File Upload Plugin Unrestricted file upload vulnerability

Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.

Пакеты

Наименование

blueimp/jquery-file-upload

composer
Затронутые версииВерсия исправления

= 6.4.4

Отсутствует

EPSS

Процентиль: 100%
0.90252
Критический

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
около 6 лет назад

Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.

EPSS

Процентиль: 100%
0.90252
Критический

Дефекты

CWE-434