vendor:
Switchblade Powerful WordPress Theme
by:
Byakuya
7,5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: Switchblade Powerful WordPress Theme
Affected Version From: v1.3
Affected Version To: v1.3
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows/Linux
2013
WordPress Switchblade Themes Arbitrary File Upload Vulnerability
A vulnerability in the WordPress Switchblade Themes allows an attacker to upload arbitrary files to the server. This is done by sending a POST request to the php.php file located in the framework/_scripts/valums_uploader/ directory. The POST request contains the malicious file which is then uploaded to the server. The uploaded file can be accessed at http://127.0.0.1/wordpress/wp-content/uploads/[year]/[month]/up.php
Mitigation:
Ensure that the WordPress Switchblade Themes is up to date and that all security patches are applied.