vendor:
Premium Gallery Manager
by:
SecurityFocus
8,8
CVSS
HIGH
Arbitrary File Upload
264
CWE
Product Name: Premium Gallery Manager
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Premium Gallery Manager plugin for WordPress Arbitrary File Upload Vulnerability
Premium Gallery Manager plugin for WordPress is prone to a vulnerability that lets attackers upload arbitrary files. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the web server process. This may facilitate unauthorized access or privilege escalation; other attacks may also be possible.
Mitigation:
Upgrade to the latest version of the plugin.