PT-2011-4260 · WordPress · Wordpress
Jesse Ou
+1
·
Published
2011-08-10
·
Updated
2016-05-31
·
CVE-2011-3129
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
WordPress versions 3.1 through 3.1.2
WordPress versions 3.2 before Beta 2
Description
The file upload functionality has unknown impact and attack vectors, possibly related to dangerous filenames, when running on hosts with dangerous security settings.
Recommendations
For WordPress versions 3.1 through 3.1.2, update to version 3.1.3 or later.
For WordPress versions 3.2 before Beta 2, update to Beta 2 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress