CVE-2015-5681
18.08.2015, 15:59
Unrestricted file upload vulnerability in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in *_uploadfolder/big/.Enginsight
Vendor | Product | Version |
---|---|---|
wpslideshow | powerplay_gallery | 3.3 |
𝑥
= Vulnerable software versions
References