6.5
CVSSv2

CVE-2014-5460

Published: 11/09/2014 Updated: 09/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 660
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin prior to 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tribulant tibulant slideshow gallery 1.4.4

tribulant tibulant slideshow gallery 1.4.5

tribulant tibulant slideshow gallery

tribulant tibulant slideshow gallery 1.4.2

tribulant tibulant slideshow gallery 1.4.3

tribulant tibulant slideshow gallery 1.4

tribulant tibulant slideshow gallery 1.4.1

Exploits

Summary: WordPress Slideshow Gallery plugin version 146 suffers from a remote shell upload vulnerability Found by: Jesus Ramirez Pichardo @whitexploit whitexploitblogspotmx/ Date: 2014-08-28 Vendor Homepage: tribulantcom/ Software: Slideshow Gallery Version: 146 Software Link: downloadswordpressorg/plugin/slidesh ...
#!/usr/bin/env python # # WordPress Slideshow Gallery 146 Shell Upload Exploit # # WordPress Slideshow Gallery plugin version 146 suffers from a remote shell upload vulnerability (CVE-2014-5460) # # Vulnerability discovered by: Jesus Ramirez Pichardo - whitexploitblogspotmx/ # # Exploit written by: Claudio Viviani - info@homelabit - h ...
WordPress Slideshow Gallery plugin version 146 shell upload exploit ...
WordPress Slideshow Gallery plugin version 146 suffers from a remote shell upload vulnerability ...