vendor:
Frontend Upload
by:
Daniel Godoy
7,5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: Frontend Upload
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: a:gtplugins:frontend_upload
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2014
Frontend Upload WordPress Plugin – File Arbitrary Upload
Frontend Upload Wordpress Plugin is vulnerable to arbitrary file upload. An attacker can upload malicious files with php extension like c99.php, shell.gif.php, etc. and access them via http://localhost/wp-content/uploads/feuGT_uploads/feuGT_1790_43000000_948109840.php
Mitigation:
Ensure that the application is configured to only allow the upload of files with the expected extensions and content types.