vendor:
Front-end-upload
by:
Adrien Thierry
7,5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: Front-end-upload
Affected Version From: 0.5.3
Affected Version To: 0.5.3
Patch Exists: YES
Related CWE: N/A
CPE: a:mondaybynoon:front-end-upload
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
WordPress front-end-upload 0.5.3 Arbitrary File Upload
Wordpress front-end-upload 0.5.3 is vulnerable to Remote File Upload. An attacker can upload a malicious file to the server by exploiting the upload.php page. If the plugin is not active, the shell can be found at http://server/wp-content/plugins/front-end-upload/FEU_DESTINATION_DIR/shell.php, else it can be found at http://server/wp-content/uploads/iti_feu_uploads/shell.php.
Mitigation:
Disable the plugin or upgrade to the latest version.