header-logo
Suggest Exploit
vendor:
Frontend Upload
by:
Daniel Godoy
7,5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: Frontend Upload
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: a:gtplugins:frontend_upload
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2014

Frontend Upload WordPress Plugin – File Arbitrary Upload

Frontend Upload Wordpress Plugin is vulnerable to arbitrary file upload. An attacker can upload malicious files with php extension like c99.php, shell.gif.php, etc. and access them via http://localhost/wp-content/uploads/feuGT_uploads/feuGT_1790_43000000_948109840.php

Mitigation:

Ensure that the application is configured to only allow the upload of files with the expected extensions and content types.
Source

Exploit-DB raw data:

# Exploit Title: Frontend Upload Wordpress Plugin - File Arbitrary Upload
# Date: 10/02/2014
# Author: Daniel Godoy
# Author Mail: DanielGodoy[at]GobiernoFederal[dot]com
# Author Web: www.delincuentedigital.com.ar
# Software: Frontend Upload
# http://codecanyon.net/item/frontend-upload/6076410?WT.ac=solid_search_item&WT.seg_1=solid_search_item&WT.z_author=gtPlugins
# Tested on: Linux
[Comment]Greetz: Ariel Orellana, TrustedBSD, Sunplace www.remoteexecution.net www.remoteexcution.com.ar

[PoC]

you can upload files with php extension. Example: c99.php, shell.gif.php, etc...

http://localhost/wp-content/uploads/feuGT_uploads/feuGT_1790_43000000_948109840.php

-------------------------
Correo enviado por medio de MailMonstruo - www.mailmonstruo.com