1 results (0.004 seconds)
CVSS: 9.8EPSS: 80%CPEs: 18EXPL: 6

CVE-2014-6446 – Infusionsoft Gravity Forms Add-on 1.5.3 - 1.5.10 - Arbitrary File Upload
https://notcve.org/view.php?id=CVE-2014-6446
26 Sep 2014 — The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php. El plugin Infusionsoft Gravity Forms 1.5.3 hasta 1.5.10 para WordPress no restringe debidamente el acceso, lo que permite a atacantes remotos subir ficheros arbitrarios y ejecutar código PHP arbitrario a través de una solicitud en utilities/code_generator.php. • https://packetstorm.news/files/id/128591 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-434: Unrestricted Upload of File with Dangerous Type •