PT-2015-4369 · Themepunch · Showbiz Pro+1
Publicado
2015-06-30
·
Atualizado
2016-11-28
·
CVE-2014-9735
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ThemePunch Slider Revolution plugin versions prior to 3.0.96
Showbiz Pro plugin version 1.7.1 and earlier
Description
The issue allows remote attackers to upload and execute arbitrary files, delete arbitrary sliders, and create, update, import, or export arbitrary sliders due to improper access restriction to administrator AJAX functionality.
Recommendations
For ThemePunch Slider Revolution plugin versions prior to 3.0.96, update to version 3.0.96 or later.
For Showbiz Pro plugin version 1.7.1 and earlier, update to a version later than 1.7.1.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Showbiz Pro
Themepunch Slider Revolution