Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x4cj-m7cx-w8jr

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in html/images.

Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in html/images.

EPSS

Процентиль: 93%
0.11619
Средний

Связанные уязвимости

nvd
около 13 лет назад

Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in html/images.

EPSS

Процентиль: 93%
0.11619
Средний