WP GPX Maps < 1.1.23 - Arbitrary File Upload
2012-06-11 00:00
Adrien ThierryStrategic Overview
StatusPatched in 1.1.23
Affected PluginWP GPX Maps
Affected Version
< 1.1.23CVSS9.8Critical
CVE
CVE-2012-6649Vulnerability Overview
WordPress WP GPX Maps Plugin before 1.1.23 allows remote attackers to execute arbitrary PHP code via improper file upload.
Technical Analysis
REMEDIATION: Update to version 1.1.23, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C