pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.
References
Configurations
History
21 Nov 2024, 02:25
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/130017/WordPress-Pixarbay-Images-2.3-XSS-Bypass-Upload-Traversal.html - Exploit | |
References | () http://seclists.org/fulldisclosure/2015/Jan/75 - Exploit | |
References | () http://www.exploit-db.com/exploits/35846 - Exploit | |
References | () http://www.openwall.com/lists/oss-security/2015/01/25/5 - | |
References | () http://www.osvdb.org/117146 - | |
References | () http://www.securityfocus.com/archive/1/534505/100/0/threaded - | |
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=1067992%40pixabay-images%2Ftrunk%2Fpixabay-images.php&old=926633%40pixabay-images%2Ftrunk%2Fpixabay-images.php - |
Information
Published : 2015-01-28 11:59
Updated : 2024-11-21 02:25
NVD link : CVE-2015-1375
Mitre link : CVE-2015-1375
CVE.ORG link : CVE-2015-1375
JSON object : View
Products Affected
pixabay_images_project
- pixabay_images
CWE
CWE-264
Permissions, Privileges, and Access Controls