WordPress 'get_allowed_mime_types()' Function CVE-2013-5739 Remote Security Weakness
BID:62421
Info
WordPress 'get_allowed_mime_types()' Function CVE-2013-5739 Remote Security Weakness
| Bugtraq ID: | 62421 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-5739 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2013 12:00AM |
| Updated: | Sep 21 2013 12:13AM |
| Credit: | Nikhil Srivastava via Secunia |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress 'get_allowed_mime_types()' Function CVE-2013-5739 Remote Security Weakness
WordPress is prone to a remote security vulnerability because it fails to prevent the upload of certain file extensions.
An authenticated attacker can exploit this issue by uploading a specially-crafted file to the affected application.
Successfully exploiting this issue makes it easier for attackers to conduct cross-site scripting attacks.
The issue is fixed in WordPress version 3.6.1.
WordPress is prone to a remote security vulnerability because it fails to prevent the upload of certain file extensions.
An authenticated attacker can exploit this issue by uploading a specially-crafted file to the affected application.
Successfully exploiting this issue makes it easier for attackers to conduct cross-site scripting attacks.
The issue is fixed in WordPress version 3.6.1.
Exploit / POC
WordPress 'get_allowed_mime_types()' Function CVE-2013-5739 Remote Security Weakness
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
WordPress 'get_allowed_mime_types()' Function CVE-2013-5739 Remote Security Weakness
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
WordPress 'get_allowed_mime_types()' Function CVE-2013-5739 Remote Security Weakness
References:
References:
- WordPress Homepage (WordPress)