PT-2017-6759 · Gravity Forms · Aviary Image Editor Add-On For Gravity Forms

Larry W. Cashdollar

+1

·

Publicado

2017-05-23

·

Atualizado

2017-06-08

·

CVE-2015-4455

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Aviary Image Editor Add-on For Gravity Forms plugin version 3.0 beta
Description The issue allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the includes/upload.php file, and then accessing it via a direct request to the file in wp-content/uploads/gform aviary.
Recommendations For Aviary Image Editor Add-on For Gravity Forms plugin version 3.0 beta, consider restricting or disabling the file upload functionality in includes/upload.php until a patch is available to prevent remote attackers from executing arbitrary code.

Exploit

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-4455

Produtos afetados

Aviary Image Editor Add-On For Gravity Forms