Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-1916

Опубликовано: 24 июн. 2022
Источник: nvd
CVSS3: 8.8
CVSS2: 8.5
EPSS Средний

Описание

In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:user_photo_project:user_photo:0.9.4:*:*:*:*:wordpress:*:*

EPSS

Процентиль: 96%
0.26475
Средний

8.8 High

CVSS3

8.5 High

CVSS2

Дефекты

CWE-434
CWE-434

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved.

EPSS

Процентиль: 96%
0.26475
Средний

8.8 High

CVSS3

8.5 High

CVSS2

Дефекты

CWE-434
CWE-434