CVE-2013-5962
30.09.2013, 22:55
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.Enginsight
Vendor | Product | Version |
---|---|---|
envato | complete_gallery_manager_plugin | 𝑥 ≤ 3.3.3 |
envato | complete_gallery_manager_plugin | 1.0.0:rev25273 |
envato | complete_gallery_manager_plugin | 1.0.1:rev25421 |
envato | complete_gallery_manager_plugin | 1.0.2:rev25487 |
envato | complete_gallery_manager_plugin | 2.0.0:rev27524 |
envato | complete_gallery_manager_plugin | 2.0.1:rev27876 |
envato | complete_gallery_manager_plugin | 2.0.2:rev28693 |
envato | complete_gallery_manager_plugin | 2.0.3:rev28734 |
envato | complete_gallery_manager_plugin | 3.0.0:rev29469 |
envato | complete_gallery_manager_plugin | 3.0.1:rev29536 |
envato | complete_gallery_manager_plugin | 3.1.0:rev30003 |
envato | complete_gallery_manager_plugin | 3.1.1:rev30900 |
envato | complete_gallery_manager_plugin | 3.2.0:rev31030 |
envato | complete_gallery_manager_plugin | 3.2.1:rev33197 |
envato | complete_gallery_manager_plugin | 3.2.2:rev33971 |
envato | complete_gallery_manager_plugin | 3.2.3:rev34390 |
envato | complete_gallery_manager_plugin | 3.2.4:rev34757 |
envato | complete_gallery_manager_plugin | 3.2.5:rev34942 |
envato | complete_gallery_manager_plugin | 3.2.6:rev36235 |
envato | complete_gallery_manager_plugin | 3.2.7:rev36257 |
envato | complete_gallery_manager_plugin | 3.2.8:rev36369 |
envato | complete_gallery_manager_plugin | 3.3.0:rev36620 |
envato | complete_gallery_manager_plugin | 3.3.1:rev38906 |
envato | complete_gallery_manager_plugin | 3.3.2:rev39009 |
𝑥
= Vulnerable software versions
References