CVE-2014-9735: WordPress RevSlider – Remote Code Execution via File Upload

CVE-2014-9735: WordPress RevSlider - Remote Code Execution via File Upload-渗透云记 - 专注于网络安全与技术分享
CVE-2014-9735: WordPress RevSlider – Remote Code Execution via File Upload
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2014-9735: WordPress RevSlider – Remote Code Execution via File Upload

漏洞描述

The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for WordPress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) delete arbitrary sliders via a delete_slider action; and (3) create, (4) update, (5) import, or (6) export arbitrary sliders via unspecified vectors.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享