1 results (0.005 seconds)

CVSS: 9.8EPSS: 66%CPEs: 18EXPL: 4

The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php. El plugin Infusionsoft Gravity Forms 1.5.3 hasta 1.5.10 para WordPress no restringe debidamente el acceso, lo que permite a atacantes remotos subir ficheros arbitrarios y ejecutar código PHP arbitrario a través de una solicitud en utilities/code_generator.php. • https://www.exploit-db.com/exploits/34925 http://osvdb.org/show/osvdb/112171 http://packetstormsecurity.com/files/131002/Wordpress-InfusionSoft-Shell-Upload.html http://research.g0blin.co.uk/cve-2014-6446 http://www.exploit-db.com/exploits/34925 https://wordpress.org/plugins/infusionsoft/changelog • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-434: Unrestricted Upload of File with Dangerous Type •