5.1
CVSSv2

CVE-2013-5962

Published: 30/09/2013 Updated: 29/08/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin prior to 3.3.4 rev40279 for WordPress allows remote malicious users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.

Vulnerable Product Search on Vulmon Subscribe to Product

envato complete gallery manager plugin 3.3.2

envato complete gallery manager plugin 3.3.1

envato complete gallery manager plugin 3.2.2

envato complete gallery manager plugin 3.2.1

envato complete gallery manager plugin 2.0.2

envato complete gallery manager plugin 2.0.1

envato complete gallery manager plugin 3.2.6

envato complete gallery manager plugin 3.2.5

envato complete gallery manager plugin 3.1.0

envato complete gallery manager plugin 3.0.1

envato complete gallery manager plugin 1.0.1

envato complete gallery manager plugin 1.0.0

envato complete gallery manager plugin 3.3.0

envato complete gallery manager plugin 3.2.8

envato complete gallery manager plugin 3.2.7

envato complete gallery manager plugin 3.2.0

envato complete gallery manager plugin 3.1.1

envato complete gallery manager plugin 2.0.0

envato complete gallery manager plugin 1.0.2

envato complete gallery manager plugin

envato complete gallery manager plugin 3.2.4

envato complete gallery manager plugin 3.2.3

envato complete gallery manager plugin 3.0.0

envato complete gallery manager plugin 2.0.3

Exploits

Title: ====== Wordpress Plugin Complete Gallery Manager 333 - Arbitrary File Upload Vulnerability Date: ===== 2013-09-17 References: =========== wwwvulnerability-labcom/get_contentphp?id=1080 VL-ID: ===== 1080 Common Vulnerability Scoring System: ==================================== 66 Introduction: ============= Using Comple ...