WordPress NextGEN Gallery 'photocrati_ajax' Arbitrary File Upload Vulnerability
BID:68414
Info
WordPress NextGEN Gallery 'photocrati_ajax' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 68414 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2014 12:00AM |
| Updated: | May 19 2014 12:00AM |
| Credit: | SANTHO |
| Vulnerable: |
WordPress NextGEN Gallery 2.0.63 WordPress NextGEN Gallery 2.0.7 WordPress NextGEN Gallery 2.0 WordPress NextGEN Gallery 1.9.13 WordPress NextGEN Gallery 1.9.12 WordPress NextGEN Gallery 1.9.11 WordPress NextGEN Gallery 1.9.10 WordPress NextGEN Gallery 1.9.5 WordPress NextGEN Gallery 1.9.1 WordPress NextGEN Gallery 1.8.4 WordPress NextGEN Gallery 1.8.3 WordPress NextGEN Gallery 1.9.7 WordPress NextGEN Gallery 1.9.6 |
| Not Vulnerable: |
WordPress NextGEN Gallery 2.65 |
Discussion
WordPress NextGEN Gallery 'photocrati_ajax' Arbitrary File Upload Vulnerability
The NextGEN Gallery plugin for WordPress is prone to a vulnerability that lets attackers upload arbitrary files.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in an arbitrary code execution within the context of the vulnerable application.
Versions prior to NextGEN Gallery 2.0.63 are vulnerable.
The NextGEN Gallery plugin for WordPress is prone to a vulnerability that lets attackers upload arbitrary files.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in an arbitrary code execution within the context of the vulnerable application.
Versions prior to NextGEN Gallery 2.0.63 are vulnerable.
Exploit / POC
WordPress NextGEN Gallery 'photocrati_ajax' Arbitrary File Upload Vulnerability
Attackers can exploit this issue through a browser.
The following exploit is available:
Attackers can exploit this issue through a browser.
The following exploit is available: