WP Symposium < 11.12.24 - Arbitrary File Upload

2011-12-28 00:00
Anonymous

Strategic Overview

Status
Patched in 11.12.24
Affected PluginWP Symposium
Affected Version< 11.12.24
CVSS8.8High
CVECVE-2011-5051
View all WP Symposium vulnerabilities

Vulnerability Overview

Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension using (1) uploadify/upload_admin_avatar.php or (2) uploadify/upload_profile_avatar.php, then accessing it via a direct request to the file in an unspecified directory inside the webroot.

Technical Analysis

REMEDIATION: Update to version 11.12.24, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C