5.1

CVE-2013-5962

Exploit

Complete Gallery Manager <= 3.3.3 - Arbitrary File Upload

Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.
Mögliche Gegenmaßnahme
Complete Gallery Manager for WordPress | Galleries: Update to version 3.3.4, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Complete Gallery Manager for WordPress | Galleries
Version [*, 3.3.4)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EnvatoComplete Gallery Manager Plugin Updaterev39177 Version <= 3.3.3
EnvatoComplete Gallery Manager Plugin Version1.0.0 Updaterev25273
EnvatoComplete Gallery Manager Plugin Version1.0.1 Updaterev25421
EnvatoComplete Gallery Manager Plugin Version1.0.2 Updaterev25487
EnvatoComplete Gallery Manager Plugin Version2.0.0 Updaterev27524
EnvatoComplete Gallery Manager Plugin Version2.0.1 Updaterev27876
EnvatoComplete Gallery Manager Plugin Version2.0.2 Updaterev28693
EnvatoComplete Gallery Manager Plugin Version2.0.3 Updaterev28734
EnvatoComplete Gallery Manager Plugin Version3.0.0 Updaterev29469
EnvatoComplete Gallery Manager Plugin Version3.0.1 Updaterev29536
EnvatoComplete Gallery Manager Plugin Version3.1.0 Updaterev30003
EnvatoComplete Gallery Manager Plugin Version3.1.1 Updaterev30900
EnvatoComplete Gallery Manager Plugin Version3.2.0 Updaterev31030
EnvatoComplete Gallery Manager Plugin Version3.2.1 Updaterev33197
EnvatoComplete Gallery Manager Plugin Version3.2.2 Updaterev33971
EnvatoComplete Gallery Manager Plugin Version3.2.3 Updaterev34390
EnvatoComplete Gallery Manager Plugin Version3.2.4 Updaterev34757
EnvatoComplete Gallery Manager Plugin Version3.2.5 Updaterev34942
EnvatoComplete Gallery Manager Plugin Version3.2.6 Updaterev36235
EnvatoComplete Gallery Manager Plugin Version3.2.7 Updaterev36257
EnvatoComplete Gallery Manager Plugin Version3.2.8 Updaterev36369
EnvatoComplete Gallery Manager Plugin Version3.3.0 Updaterev36620
EnvatoComplete Gallery Manager Plugin Version3.3.1 Updaterev38906
EnvatoComplete Gallery Manager Plugin Version3.3.2 Updaterev39009
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 26.58% 0.962
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.