7.5
CVSSv2

CVE-2014-9473

Published: 08/01/2015 Updated: 08/01/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and previous versions for WordPress allows remote malicious users to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file via a direct request to the file in the default upload directory.

Vulnerable Product Search on Vulmon Subscribe to Product

deliciousdays cformsii

Exploits

# Exploit Title: Remote Code Execution via Unauthorised File upload in Cforms 147 # Date: 2015-01-19 # Exploit Author: Zakhar # Vendor Homepage: wordpressorg/plugins/cforms2/ # Software Link: downloadswordpressorg/plugin/cforms2zip # Version: 147 # Tested on: Wordpress 40 # CVE : 2014-9473 import os import requests import r ...