9.8

CVE-2014-8739

Exploit

Creative Contact Form < 1.0.0 - Arbitrary File Upload

Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.
Mögliche Gegenmaßnahme
Creative Contact Form: Update to version 1.0.0, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Creative-solutionsCreative Contact Form SwPlatformwordpress Version < 1.0.0
Creative-solutionsCreative Contact Form SwPlatformjoomla! Version < 2.0.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Creative Contact Form
Version [*, 1.0.0)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 91.66% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

http://osvdb.org/show/osvdb/113669
Broken Link
http://osvdb.org/show/osvdb/113673
Broken Link
http://www.openwall.com/lists/oss-security/2014/11/11/4
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2014/11/11/5
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2014/11/13/3
Third Party Advisory
Mailing List
https://wordpress.org/plugins/sexy-contact-form/changelog/
Third Party Advisory
https://www.exploit-db.com/exploits/35057/
Third Party Advisory
Exploit
VDB Entry
https://www.exploit-db.com/exploits/36811/
Third Party Advisory
Exploit
VDB Entry
https://www.wordfence.com/threat-intel/vulnerabilities/id/39ced195-63a7-4f50-a4eb-b43d6069f7e1
Third Party Advisory