Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to upload and execute arbitrary PHP files via the Upload section in the Write Tabs area of the dashboard.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/29276 | Third Party Advisory VDB Entry |
http://securityreason.com/securityalert/3897 | Third Party Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42561 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/archive/1/492230/100/0/threaded | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2008-05-21 06:24
Updated : 2018-10-31 11:37
NVD link : CVE-2008-2392
Mitre link : CVE-2008-2392
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
wordpress
- wordpress