Lucene search

K
patchstackDVtoolsPATCHSTACK:842C62AE64178D33D1A760EC3A4A5F23
HistoryFeb 17, 2011 - 12:00 a.m.

WordPress User Photo Component - Remote File Upload

2011-02-1700:00:00
DVtools
patchstack.com
4

EPSS

0.033

Percentile

91.4%

Remote file upload vulnerability was found in this plugin. When photo is uploaded, it is validated only partially. There is a possibility to upload a backdoor on the server hosting WordPress and it can be executed independently from that if the photo has not been yet approved. Also, there is a cross-site scripting vulnerability .

Solution

           This vulnerability can be limited by hardening of the web server. 

EPSS

0.033

Percentile

91.4%

Related for PATCHSTACK:842C62AE64178D33D1A760EC3A4A5F23