6.8
CVSSv2

CVE-2013-5961

Published: 30/09/2013 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote malicious users to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.

Vulnerable Product Search on Vulmon Subscribe to Product

danny_morris lazy_seo 1.1.9

Exploits

####################################################################### # Exploit Title : Wordpress Lazy SEO plugin Shell Upload Vulnerability # # Exploit Author : Ashiyane Digital Security Team # # Google Dork: : inurl:/wp-content/plugins/lazy-seo/ # # Date: 2013/09/21 # # Vendor Homepage : wordpressorg/plugins/lazy-seo # # Software Link ...