CVE-2013-5963

Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/wpdb/.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
cdsincdesignsimple_dropbox_upload_form
𝑥
≤ 1.8.8
cdsincdesignsimple_dropbox_upload_form
0.5.0
cdsincdesignsimple_dropbox_upload_form
1.0.0
cdsincdesignsimple_dropbox_upload_form
1.1.0
cdsincdesignsimple_dropbox_upload_form
1.1.1
cdsincdesignsimple_dropbox_upload_form
1.1.2
cdsincdesignsimple_dropbox_upload_form
1.2.0
cdsincdesignsimple_dropbox_upload_form
1.3.0
cdsincdesignsimple_dropbox_upload_form
1.3.1
cdsincdesignsimple_dropbox_upload_form
1.4.0
cdsincdesignsimple_dropbox_upload_form
1.5.0
cdsincdesignsimple_dropbox_upload_form
1.5.1
cdsincdesignsimple_dropbox_upload_form
1.5.2
cdsincdesignsimple_dropbox_upload_form
1.5.3
cdsincdesignsimple_dropbox_upload_form
1.6.0
cdsincdesignsimple_dropbox_upload_form
1.7.0
cdsincdesignsimple_dropbox_upload_form
1.8.0
cdsincdesignsimple_dropbox_upload_form
1.8.1
cdsincdesignsimple_dropbox_upload_form
1.8.2
cdsincdesignsimple_dropbox_upload_form
1.8.3
cdsincdesignsimple_dropbox_upload_form
1.8.4
cdsincdesignsimple_dropbox_upload_form
1.8.5
cdsincdesignsimple_dropbox_upload_form
1.8.6
cdsincdesignsimple_dropbox_upload_form
1.8.7
𝑥
= Vulnerable software versions