10
CVSSv2

CVE-2008-3362

Published: 30/07/2008 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote malicious users to execute arbitrary code by uploading a file with an executable extension via the upfile parameter, then accessing it via a direct request to the file in wp-content/plugins/downloads-manager/upload/.

Vulnerable Product Search on Vulmon Subscribe to Product

giulio ganci wp downloads manager 0.2

wordpress wp downloads manager 0.2

Exploits

<a name="upload-file"></a><h2>WORDPRESS PLUGIN DOWNLOAD MANAGER 02 REMOTE FILE UPLOAD</h2> <h3>SaO</h3> <h4>BiyoSecurityTeam || wwwbiyosecuritycom</h4> <i>Plugin URI: giuliogancinetsonsorg/downloads-manager<i> <hr color="#f0f8ff"> <fieldset name="upl" class="op ...