CVE-2014-8739: WordPress Sexy Contact Form (<= 0.9.7) - Arbitrary File Upload

CVE-2014-8739: WordPress Sexy Contact Form (<= 0.9.7) - Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享
CVE-2014-8739: WordPress Sexy Contact Form (<= 0.9.7) - Arbitrary File Upload
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2014-8739: WordPress Sexy Contact Form (<= 0.9.7) – Arbitrary File Upload

漏洞描述

Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享