6.5
CVE-2007-3544
- EPSS 1.08%
- Veröffentlicht 03.07.2007 20:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
WordPress Core <= 2.2.1 - Arbitrary File Upload
Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-3543.
Mögliche Gegenmaßnahme
WordPress: Update to version 2.2.2, or a newer patched version
WordPress MU: Update to version 1.2.4, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Core
≫
Produkt
WordPress
Version
* - 2.2.1
SystemWordPress Core
≫
Produkt
WordPress MU
Version
* - 1.2.3
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wordpress ≫ Wordpress Mu Version <= 1.2.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.08% | 0.772 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|