Описание
Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/wpdb/.
Комментарий
Per: http://cwe.mitre.org/data/definitions/434.html
'CWE-434: Unrestricted Upload of File with Dangerous Type'
Ссылки
- Exploit
- Vendor Advisory
- ExploitPatch
- Exploit
- Vendor Advisory
- ExploitPatch
Уязвимые конфигурации
Одновременно
Одно из
EPSS
6.8 Medium
CVSS2
Дефекты
Связанные уязвимости
Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/wpdb/.
EPSS
6.8 Medium
CVSS2