CVE-2007-3543
WordPress Core <= 2.2 - Arbitrary File Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the _wp_attached_file metadata field; and then sending this file's content, along with its post_ID value, to (1) wp-app.php or (2) app.php.
Vulnerabilidad de fichero de archivo no restringido en WordPress anterior a 2.2.1 y WordPress MU anterior a 1.2.3 permite a usuarios autenticados remotos subir y ejecutar código PHP de su elección mediante un post en el que se especifica un nombre de fichero .php en el campo de meta datos _wp_attached_file; entonces se envía el contenido del fichero, junto con su valor post_ID, a (1) wp-app.php o (2) app.php.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-07-03 CVE Reserved
- 2007-07-03 CVE Published
- 2024-05-06 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://osvdb.org/37295 | Vdb Entry | |
http://trac.mu.wordpress.org/changeset/1005 | X_refsource_confirm | |
http://www.buayacorp.com/files/wordpress/wordpress-advisory.html | X_refsource_misc | |
http://www.securityfocus.com/bid/24642 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/25794 | 2008-11-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | <= 2.2.0 Search vendor "Wordpress" for product "Wordpress" and version " <= 2.2.0" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Mu Search vendor "Wordpress" for product "Wordpress Mu" | <= 1.2.2 Search vendor "Wordpress" for product "Wordpress Mu" and version " <= 1.2.2" | - |
Affected
|