vendor:
Foxypress plugin
by:
Sammy FORGIT, patrick
N/A
CVSS
N/A
Arbitrary Code Execution
N/A
CWE
Product Name: Foxypress plugin
Affected Version From: 0.4.2.1
Affected Version To: 0.4.2.1
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress
2012
WordPress plugin Foxypress uploadify.php Arbitrary Code Execution
This module exploits an arbitrary PHP code execution flaw in the WordPress blogging software plugin known as Foxypress. The vulnerability allows for arbitrary file upload and remote code execution via the uploadify.php script. The Foxypress plug-in versions 0.4.2.1 and below are vulnerable.
Mitigation:
Upgrade to the latest version of Foxypress plugin