1 results (0.001 seconds)

CVSS: 9.8EPSS: 7%CPEs: 1EXPL: 5

01 Jul 2015 — Unrestricted file upload vulnerability in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in *_uploadfolder/big/. Vulnerabilidad de subida de archivo no restringido en upload.php en el plugin Powerplay Gallery 3.3 para WordPress, permite a atacantes remotos ejecutar código arbitrario subiendo un archivo con una extensión ejecutable, accediendo en... • http://packetstormsecurity.com/files/132671/WordPress-WP-PowerPlayGallery-3.3-File-Upload-SQL-Injection.html • CWE-434: Unrestricted Upload of File with Dangerous Type •