WordPress cformsII Plugin 'lib_nonajax.php' Arbitrary File Upload Vulnerability
BID:71818
Info
WordPress cformsII Plugin 'lib_nonajax.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 71818 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2014 12:00AM |
| Updated: | Dec 29 2014 12:00AM |
| Credit: | Zakhar Fedotkin |
| Vulnerable: |
WordPress cformsII 14.7 |
| Not Vulnerable: |
WordPress cformsII 14.8 |
Discussion
WordPress cformsII Plugin 'lib_nonajax.php' Arbitrary File Upload Vulnerability
The cformsII plugin for WordPress is prone to an arbitrary file-upload vulnerability because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
The cformsII plugin for WordPress is prone to an arbitrary file-upload vulnerability because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
References
WordPress cformsII Plugin 'lib_nonajax.php' Arbitrary File Upload Vulnerability
References:
References:
- cformsII Homepage (Oliver Seidel)
- Remote Code Execution via Unauthorised File upload in Cforms 14.7 (z.fedotkin)
- WordPress HomePage (WordPress)