WordPress 'wp-admin/includes/file.php' Arbitrary File Upload Vulnerability
BID:37005
Info
WordPress 'wp-admin/includes/file.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 37005 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2009 12:00AM |
| Updated: | Apr 13 2015 09:30PM |
| Credit: | Dawid Golunski |
| Vulnerable: |
WordPress WordPress 2.8.5 WordPress WordPress 2.8.4 WordPress WordPress 2.8.3 WordPress WordPress 2.8.2 WordPress WordPress 2.8.1 WordPress WordPress 2.8 |
| Not Vulnerable: |
WordPress WordPress 2.8.6 |
Discussion
WordPress 'wp-admin/includes/file.php' Arbitrary File Upload Vulnerability
WordPress is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Note that this issue arises only in certain Apache configurations that use the Add* directives and PHP to facilitate handling of files with multiple extensions.
WordPress 2.8.5 and prior versions are vulnerable.
WordPress is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Note that this issue arises only in certain Apache configurations that use the Add* directives and PHP to facilitate handling of files with multiple extensions.
WordPress 2.8.5 and prior versions are vulnerable.
Exploit / POC
WordPress 'wp-admin/includes/file.php' Arbitrary File Upload Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
WordPress 'wp-admin/includes/file.php' Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references for details.
WordPress WordPress 2.8
WordPress WordPress 2.8.1
WordPress WordPress 2.8.2
WordPress WordPress 2.8.3
WordPress WordPress 2.8.4
WordPress WordPress 2.8.5
Solution:
Updates are available. Please see the references for details.
WordPress WordPress 2.8
-
WordPress wordpress-2.8.6.zip
http://wordpress.org/wordpress-2.8.6.zip
WordPress WordPress 2.8.1
-
WordPress wordpress-2.8.6.zip
http://wordpress.org/wordpress-2.8.6.zip
WordPress WordPress 2.8.2
-
WordPress wordpress-2.8.6.zip
http://wordpress.org/wordpress-2.8.6.zip
WordPress WordPress 2.8.3
-
WordPress wordpress-2.8.6.zip
http://wordpress.org/wordpress-2.8.6.zip
WordPress WordPress 2.8.4
-
WordPress wordpress-2.8.6.zip
http://wordpress.org/wordpress-2.8.6.zip
WordPress WordPress 2.8.5
-
WordPress wordpress-2.8.6.zip
http://wordpress.org/wordpress-2.8.6.zip
References
WordPress 'wp-admin/includes/file.php' Arbitrary File Upload Vulnerability
References:
References: