PT-2015-7032 · WordPress · Powerplay Gallery Plugin
Larry W. Cashdollar
+1
·
Publicado
2015-08-18
·
Atualizado
2015-08-19
·
CVE-2015-5681
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Powerplay Gallery plugin version 3.3 for WordPress
Description
The issue concerns an unrestricted file upload vulnerability. This allows remote attackers to execute arbitrary code by uploading a file with an executable extension and then accessing it directly. The vulnerability is specifically in the upload.php file of the Powerplay Gallery plugin.
Recommendations
For Powerplay Gallery plugin version 3.3, consider disabling the upload functionality in upload.php until a patch is available to prevent remote attackers from uploading malicious files. Restrict access to the * uploadfolder/big/ directory to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Powerplay Gallery Plugin