CVE-2014-4972
08.01.2018, 19:29
Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under wp-content/uploads/gravity_forms.Enginsight
Vendor | Product | Version |
---|---|---|
ajax_upload_for_gravity_forms_project | ajax_upload_for_gravity_forms | 𝑥 ≤ 1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration