CVE-2021-24236: WordPress Imagements <=1.2.5 - Arbitrary File Upload

CVE-2021-24236: WordPress Imagements <=1.2.5 - Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享
CVE-2021-24236: WordPress Imagements <=1.2.5 - Arbitrary File Upload
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-24236: wordpress Imagements <=1.2.5 – Arbitrary File Upload

漏洞描述

WordPress Imagements plugin through 1.2.5 is susceptible to arbitrary file upload which can lead to remote code execution. The plugin allows images to be uploaded in comments but only checks for the Content-Type in the request to forbid dangerous files. An attacker can upload arbitrary files by using a valid image Content-Type along with a PHP filename and code.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享