CVE-2017-1002001
Mobile App Builder by WapPress <= 1.05 - Arbitrary File Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
Existe una vulnerabilidad en el plugin mobile-app-builder-by-wappress v1.05 de WordPress. Este plugin incluye software CMS vulnerable sin licencia de http://www.invedion.com.
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com. There are no file upload authentication or capability checks which make it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
WordPress plugins Zen App Mobile Native versions 3.0 and below, webapp-builder version 2.0, wp2android-turn-wp-site-into-android-app version 1.1.4, mobile-app-builder-by-wappress version 1.05, and mobile-friendly-app-builder-by-easytouch version 3.0 suffer from a remote shell upload vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-03-07 CVE Published
- 2017-09-14 CVE Reserved
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-08-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://wordpress.org/plugins-wp/mobile-app-builder-by-wappress | Not Applicable |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/41540 | 2024-08-05 | |
http://www.vapidlabs.com/advisory.php?v=180 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mobile-app-builder-by-wappress Project Search vendor "Mobile-app-builder-by-wappress Project" | Mobile-app-builder-by-wappress Search vendor "Mobile-app-builder-by-wappress Project" for product "Mobile-app-builder-by-wappress" | 1.05 Search vendor "Mobile-app-builder-by-wappress Project" for product "Mobile-app-builder-by-wappress" and version "1.05" | wordpress |
Affected
|