vendor:
dzs-videogallery
by:
iskorpitx
7,5
CVSS
HIGH
Remote File Upload Vulnerability
434
CWE
Product Name: dzs-videogallery
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows/Linux
2013
WordPress dzs-videogallery Plugins Remote File Upload Vulnerability
A vulnerability in the WordPress dzs-videogallery plugin allows an attacker to upload arbitrary files to the server. The vulnerable file is upload.php, which is located in the /wp-content/plugins/dzs-videogallery/admin/dzsuploader/ directory. An attacker can exploit this vulnerability by sending a specially crafted HTTP POST request to the upload.php file. This will allow the attacker to upload arbitrary files to the server, which can then be used to execute arbitrary code.
Mitigation:
Update to the latest version of the plugin.