5.1

CVE-2013-5962

Exploit

Complete Gallery Manager <= 3.3.3 - Arbitrary File Upload

Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.
Mögliche Gegenmaßnahme
Complete Gallery Manager for WordPress | Galleries: Update to version 3.3.4, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EnvatoComplete Gallery Manager Plugin Updaterev39177 Version <= 3.3.3
EnvatoComplete Gallery Manager Plugin Version1.0.0 Updaterev25273
EnvatoComplete Gallery Manager Plugin Version1.0.1 Updaterev25421
EnvatoComplete Gallery Manager Plugin Version1.0.2 Updaterev25487
EnvatoComplete Gallery Manager Plugin Version2.0.0 Updaterev27524
EnvatoComplete Gallery Manager Plugin Version2.0.1 Updaterev27876
EnvatoComplete Gallery Manager Plugin Version2.0.2 Updaterev28693
EnvatoComplete Gallery Manager Plugin Version2.0.3 Updaterev28734
EnvatoComplete Gallery Manager Plugin Version3.0.0 Updaterev29469
EnvatoComplete Gallery Manager Plugin Version3.0.1 Updaterev29536
EnvatoComplete Gallery Manager Plugin Version3.1.0 Updaterev30003
EnvatoComplete Gallery Manager Plugin Version3.1.1 Updaterev30900
EnvatoComplete Gallery Manager Plugin Version3.2.0 Updaterev31030
EnvatoComplete Gallery Manager Plugin Version3.2.1 Updaterev33197
EnvatoComplete Gallery Manager Plugin Version3.2.2 Updaterev33971
EnvatoComplete Gallery Manager Plugin Version3.2.3 Updaterev34390
EnvatoComplete Gallery Manager Plugin Version3.2.4 Updaterev34757
EnvatoComplete Gallery Manager Plugin Version3.2.5 Updaterev34942
EnvatoComplete Gallery Manager Plugin Version3.2.6 Updaterev36235
EnvatoComplete Gallery Manager Plugin Version3.2.7 Updaterev36257
EnvatoComplete Gallery Manager Plugin Version3.2.8 Updaterev36369
EnvatoComplete Gallery Manager Plugin Version3.3.0 Updaterev36620
EnvatoComplete Gallery Manager Plugin Version3.3.1 Updaterev38906
EnvatoComplete Gallery Manager Plugin Version3.3.2 Updaterev39009
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Complete Gallery Manager for WordPress | Galleries
Version [*, 3.3.4)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 14.77% 0.962
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2013-09/0090.html
Exploit
http://codecanyon.net/item/complete-gallery-manager-for-wordpress/2418606
http://packetstormsecurity.com/files/123303
Exploit
http://secunia.com/advisories/54894
Vendor Advisory
http://www.exploit-db.com/exploits/28377
http://www.vulnerability-lab.com/get_content.php?id=1080
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/87172
https://www.wordfence.com/threat-intel/vulnerabilities/id/09c59fb5-8264-4277-a821-dbfee0900f64
Third Party Advisory