vendor:
Infusionsoft Gravity Forms
by:
g0blin and us3r777 <us3r777@n0b0.so>
N/A
CVSS
N/A
Arbitrary File Upload and Remote Code Execution
434
CWE
Product Name: Infusionsoft Gravity Forms
Affected Version From: 1.5.3
Affected Version To: 1.5.10
Patch Exists: YES
Related CWE: CVE-2014-6446
CPE: a:infusionsoft:infusionsoft_gravity_forms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
2014
WordPress InfusionSoft Upload Vulnerability
This module exploits an arbitrary PHP code upload in the wordpress Infusionsoft Gravity Forms plugin, versions from 1.5.3 to 1.5.10. The vulnerability allows for arbitrary file upload and remote code execution.
Mitigation:
Update the plugin to the latest version