9.8

CVE-2016-15043

Medienbericht
Exploit

WP Mobile Detector <= 3.5 - Arbitrary File Upload

WP Mobile Detector <= 3.5 - Arbitrary File Upload

The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Mögliche Gegenmaßnahme
WP Mobile Detector: Update to version 3.6, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wp Mobile Detector ProjectWp Mobile Detector SwPlatformwordpress Version <= 3.5
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt WP Mobile Detector
Version *-3.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.03% 0.95
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://www.wordfence.com/threat-intel/vulnerabilities/id/5a5d5dbd-36f0-4886-adf8-045ec9c2e306?source=cve
Third Party Advisory
https://blog.sucuri.net/2016/06/wp-mobile-detector-vulnerability-being-exploited-in-the-wild.html
Exploit
Press/Media Coverage
https://www.pluginvulnerabilities.com/2016/05/31/aribitrary-file-upload-vulnerability-in-wp-mobile-detector/
Third Party Advisory
Exploit
https://wordpress.org/plugins/wp-mobile-detector/changelog/
Product
https://wpscan.com/vulnerability/e4739674-eed4-417e-8c4d-2f5351b057cf
Third Party Advisory
Exploit
https://aadityapurani.com/2016/06/03/mobile-detector-poc/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/5a5d5dbd-36f0-4886-adf8-045ec9c2e306
Third Party Advisory