MEDIUM
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/
Published Sep 30, 2013
5.1
MEDIUMCVSS 2.0
EPSS 14.77%
Description
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.
Affected products
No data.
OR
- ≤ 3.3.3
- 1.0.0
- 1.0.1
- 1.0.2
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 3.0.0
- 3.0.1
- 3.1.0
- 3.1.1
- 3.2.0
- 3.2.1
- 3.2.2
- 3.2.3
- 3.2.4
- 3.2.5
- 3.2.6
- 3.2.7
- 3.2.8
- 3.3.0
- 3.3.1
- 3.3.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (7)
- http://archives.neohapsis.com/archives/bugtraq/2013-09/0090.html mailing-listx_refsource_BUGTRAQExploit
- http://codecanyon.net/item/complete-gallery-manager-for-wordpress/2418606 x_refsource_CONFIRM
- http://packetstormsecurity.com/files/123303 x_refsource_MISCExploit
- http://secunia.com/advisories/54894 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.exploit-db.com/exploits/28377 exploitx_refsource_EXPLOIT-DB
- http://www.vulnerability-lab.com/get_content.php?id=1080 x_refsource_MISCExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87172 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2013-09/0090.html | mailing-listx_refsource_BUGTRAQExploit | |
| http://codecanyon.net/item/complete-gallery-manager-for-wordpress/2418606 | x_refsource_CONFIRM | |
| http://packetstormsecurity.com/files/123303 | x_refsource_MISCExploit | |
| http://secunia.com/advisories/54894 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.exploit-db.com/exploits/28377 | exploitx_refsource_EXPLOIT-DB | |
| http://www.vulnerability-lab.com/get_content.php?id=1080 | x_refsource_MISCExploit | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/87172 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 30, 2013
Updated Aug 6, 2024
Reserved Sep 30, 2013
Link CVE-2013-5962
CISA Vulnrichment
Updated n/a