PT-2015-4369 · Themepunch · Showbiz Pro+1

Publicado

2015-06-30

·

Atualizado

2016-11-28

·

CVE-2014-9735

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ThemePunch Slider Revolution plugin versions prior to 3.0.96 Showbiz Pro plugin version 1.7.1 and earlier
Description The issue allows remote attackers to upload and execute arbitrary files, delete arbitrary sliders, and create, update, import, or export arbitrary sliders due to improper access restriction to administrator AJAX functionality.
Recommendations For ThemePunch Slider Revolution plugin versions prior to 3.0.96, update to version 3.0.96 or later. For Showbiz Pro plugin version 1.7.1 and earlier, update to a version later than 1.7.1.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-9735

Produtos afetados

Showbiz Pro
Themepunch Slider Revolution