Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to upload and execute arbitrary PHP files via the Upload section in the Write Tabs area of the dashboard.
References
Link | Resource |
---|---|
http://securityreason.com/securityalert/3897 | Third Party Advisory |
http://www.securityfocus.com/archive/1/492230/100/0/threaded | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/29276 | Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42561 | Third Party Advisory VDB Entry |
http://securityreason.com/securityalert/3897 | Third Party Advisory |
http://www.securityfocus.com/archive/1/492230/100/0/threaded | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/29276 | Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42561 | Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 00:46
Type | Values Removed | Values Added |
---|---|---|
References | () http://securityreason.com/securityalert/3897 - Third Party Advisory | |
References | () http://www.securityfocus.com/archive/1/492230/100/0/threaded - Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/29276 - Third Party Advisory, VDB Entry | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/42561 - Third Party Advisory, VDB Entry |
Information
Published : 2008-05-21 13:24
Updated : 2024-11-21 00:46
NVD link : CVE-2008-2392
Mitre link : CVE-2008-2392
CVE.ORG link : CVE-2008-2392
JSON object : View
Products Affected
wordpress
- wordpress
CWE
CWE-20
Improper Input Validation