Lucene search

K
cveMitreCVE-2015-1375
HistoryJan 28, 2015 - 11:59 a.m.

CVE-2015-1375

2015-01-2811:59:00
CWE-264
mitre
web.nvd.nist.gov
28
pixabay images
wordpress
cve-2015-1375
security vulnerability
file upload

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.142

Percentile

95.8%

pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.

Affected configurations

Nvd
Node
pixabay_images_projectpixabay_imagesRange2.3wordpress
VendorProductVersionCPE
pixabay_images_projectpixabay_images*cpe:2.3:a:pixabay_images_project:pixabay_images:*:*:*:*:*:wordpress:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.142

Percentile

95.8%

Related for CVE-2015-1375