CVE-2013-5962

Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
envatocomplete_gallery_manager_plugin
𝑥
≤ 3.3.3
envatocomplete_gallery_manager_plugin
1.0.0:rev25273
envatocomplete_gallery_manager_plugin
1.0.1:rev25421
envatocomplete_gallery_manager_plugin
1.0.2:rev25487
envatocomplete_gallery_manager_plugin
2.0.0:rev27524
envatocomplete_gallery_manager_plugin
2.0.1:rev27876
envatocomplete_gallery_manager_plugin
2.0.2:rev28693
envatocomplete_gallery_manager_plugin
2.0.3:rev28734
envatocomplete_gallery_manager_plugin
3.0.0:rev29469
envatocomplete_gallery_manager_plugin
3.0.1:rev29536
envatocomplete_gallery_manager_plugin
3.1.0:rev30003
envatocomplete_gallery_manager_plugin
3.1.1:rev30900
envatocomplete_gallery_manager_plugin
3.2.0:rev31030
envatocomplete_gallery_manager_plugin
3.2.1:rev33197
envatocomplete_gallery_manager_plugin
3.2.2:rev33971
envatocomplete_gallery_manager_plugin
3.2.3:rev34390
envatocomplete_gallery_manager_plugin
3.2.4:rev34757
envatocomplete_gallery_manager_plugin
3.2.5:rev34942
envatocomplete_gallery_manager_plugin
3.2.6:rev36235
envatocomplete_gallery_manager_plugin
3.2.7:rev36257
envatocomplete_gallery_manager_plugin
3.2.8:rev36369
envatocomplete_gallery_manager_plugin
3.3.0:rev36620
envatocomplete_gallery_manager_plugin
3.3.1:rev38906
envatocomplete_gallery_manager_plugin
3.3.2:rev39009
𝑥
= Vulnerable software versions