WordPress Generic Plugin Arbitrary File Upload Vulnerability
BID:54440
Info
WordPress Generic Plugin Arbitrary File Upload Vulnerability
| Bugtraq ID: | 54440 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2012 12:00AM |
| Updated: | Jul 13 2012 12:00AM |
| Credit: | KedAns-Dz |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Generic Plugin Arbitrary File Upload Vulnerability
The Generic Plugin for WordPress is prone to an arbitrary-file-upload vulnerability.
An attacker can exploit this issue to upload arbitrary PHP code and run it in the context of the Web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Generic Plugin 0.1 is vulnerable; other versions are also affected.
The Generic Plugin for WordPress is prone to an arbitrary-file-upload vulnerability.
An attacker can exploit this issue to upload arbitrary PHP code and run it in the context of the Web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Generic Plugin 0.1 is vulnerable; other versions are also affected.
Exploit / POC
WordPress Generic Plugin Arbitrary File Upload Vulnerability
Attackers may exploit this issue through a browser.
The following exploit code is available:
Attackers may exploit this issue through a browser.
The following exploit code is available:
Solution / Fix
WordPress Generic Plugin Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
WordPress Generic Plugin Arbitrary File Upload Vulnerability
References:
References:
- WordPress Homepage (WordPress)