vendor:
SAICO
by:
Byakuya
7,5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: SAICO
Affected Version From: v1.0
Affected Version To: v1.0.2
Patch Exists: YES
Related CWE: N/A
CPE: a:themeforest:saico
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress
2013
WordPress SAICO theme Arbitrary File Upload Vulnerability
An arbitrary file upload vulnerability in the WordPress SAICO theme allows an attacker to upload a malicious PHP file to the server. This can be done by sending a POST request to the php.php file in the framework/_scripts/valums_uploader/ directory with the malicious file as a parameter. The malicious file can then be accessed at the path http://site.com/wordpress/wp-content/uploads/2013/10/up.php
Mitigation:
Ensure that the application is up to date and that all security patches are applied. Additionally, ensure that the application is configured to only allow the upload of files with the appropriate MIME type.