WordPress Plugin Wp-FileManager 'ajaxfilemanager.php' Arbitrary File Upload Vulnerability
BID:27151
Info
WordPress Plugin Wp-FileManager 'ajaxfilemanager.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 27151 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-0222 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | H-T Team discovered this vulnerability. |
| Vulnerable: |
Wp-FileManager Wp-FileManager 1.2 |
| Not Vulnerable: | |
Discussion
WordPress Plugin Wp-FileManager 'ajaxfilemanager.php' Arbitrary File Upload Vulnerability
WordPress plugin Wp-FileManager is prone to a vulnerability that attackers can exploit to upload arbitrary PHP script code and execute it in the context of the webserver process.
This issue affects WP-FileManager 1.2; other versions may also be vulnerable.
WordPress plugin Wp-FileManager is prone to a vulnerability that attackers can exploit to upload arbitrary PHP script code and execute it in the context of the webserver process.
This issue affects WP-FileManager 1.2; other versions may also be vulnerable.
Exploit / POC
WordPress Plugin Wp-FileManager 'ajaxfilemanager.php' Arbitrary File Upload Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
WordPress Plugin Wp-FileManager 'ajaxfilemanager.php' Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
WordPress Plugin Wp-FileManager 'ajaxfilemanager.php' Arbitrary File Upload Vulnerability
References:
References:
- Wp-FileManager Homepage (Wp-FileManager)