9.8
CVSSv3

CVE-2015-4455

Published: 23/05/2017 Updated: 08/06/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows remote malicious users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/gform_aviary.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

aviary image editor add-on for gravity forms project aviary image editor add-on for gravity forms

Exploits

Title: Remote file upload vulnerability in aviary-image-editor-add-on-for-gravity-forms v30beta Wordpress plugin Author: Larry W Cashdollar, @_larry0 Date: 2015-06-07 Download Site: wordpressorg/plugins/aviary-image-editor-add-on-for-gravity-forms Vendor: Waters Edge Web Design and NetherWorks LLC Vendor Notified: 2015-06-08 Advisory: ht ...