Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-1011

Опубликовано: 07 фев. 2012
Источник: nvd
CVSS2: 7.5
EPSS Средний

Описание

actions.php in the AllWebMenus plugin 1.1.8 for WordPress allows remote attackers to bypass intended access restrictions to upload and execute arbitrary PHP code by setting the HTTP_REFERER to a certain value, then uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:likno:allwebmenus_plugin:1.1.8:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.15556
Средний

7.5 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
около 3 лет назад

actions.php in the AllWebMenus plugin 1.1.8 for WordPress allows remote attackers to bypass intended access restrictions to upload and execute arbitrary PHP code by setting the HTTP_REFERER to a certain value, then uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.

EPSS

Процентиль: 94%
0.15556
Средний

7.5 High

CVSS2

Дефекты

CWE-264