vendor:
Relocate Upload Plugin
by:
Ben Schmidt
9.3
CVSS
HIGH
Remote File Inclusion (RFI)
98
CWE
Product Name: Relocate Upload Plugin
Affected Version From: 0.14
Affected Version To: 0.14
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
Relocate Upload WordPress plugin RFI
The Relocate Upload Wordpress plugin is vulnerable to a Remote File Inclusion (RFI) attack. An attacker can send a malicious request to the relocate-upload.php script with a crafted URL containing an arbitrary file path in the 'abspath' parameter. This allows the attacker to execute arbitrary code on the vulnerable server.
Mitigation:
The best way to mitigate this vulnerability is to upgrade to the latest version of the Relocate Upload plugin. Additionally, the web server should be configured to only allow requests to the relocate-upload.php script from trusted sources.