vendor:
DesignFolio-Plus
by:
CrashBandicot
7.5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: DesignFolio-Plus
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: MsWin32
2015
WordPress Theme DesignFolio+ Arbitrary File Upload Vulnerability
The exploit allows an attacker to upload arbitrary files to the target system using the vulnerable upload-file.php file. The exploit code is written in Perl and uses various modules such as Digest::MD5, MIME::Base64, IO::Socket, and LWP::UserAgent.
Mitigation:
The vendor should release a patch that fixes the vulnerability in the upload-file.php file. In the meantime, users can mitigate the risk by restricting access to the vulnerable file or removing it from the system.