CVE-2014-6446

The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.3
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.4
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.4.1
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.4.2
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.5
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.6
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.7
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.7.1
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.7.2
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.8
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.8.1
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.9
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.9.1
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.9.2
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.9.3
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.9.4
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.9.5
infusionsoft_gravity_forms_projectinfusionsoft_gravity_forms
1.5.10
𝑥
= Vulnerable software versions