E20-5qo41
CVSS:
9.0 (AV:N/AC:L/Au:N/C:P/I:P/A:C)
False Positive:
t
Variants:
64
Year:
2014
Description
An arbitrary file upload vulnerability exists in WordPress Cherry Plugin versions before 1.7, due to lack of authentication for file import actions. By exploiting this flaw, a remote unauthenticated attacker may execute arbitrary PHP code by uploading a webshell with a crafted HTTP POST request.
CVE
References
MSB
BID
ExploitDB
Secunia
Security Tracker
Metasploit
ZDI
OSVDB
{}