CVE-2014-9473 – cformsII < 14.8 - Arbitrary File Upload
https://notcve.org/view.php?id=CVE-2014-9473
Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file via a direct request to the file in the default upload directory. Vulnerabilidad de la subida de ficheros sin restricciones en lib_nonajax.php en el plugin CformsII 14.7 y anteriores para WordPress permite a atacantes remotos ejecutar código arbitrario mediante la subida de un fichero con una extensión ejecutable a través del parámetro cf_uploadfile2[], posteriormente accediendo a ello a través de una solicitud directa al fichero en el directorio de subidas por defecto. • https://www.exploit-db.com/exploits/35879 http://www.securityfocus.com/archive/1/534349/30/0/threaded https://wordpress.org/plugins/cforms2/changelog • CWE-434: Unrestricted Upload of File with Dangerous Type •