Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-9308

Overview

Vulnerability Score 6.5 6.5
CVE Id CVE-2014-9308
Last Modified 16 Jan 2015 11:29:21
Published 15 Jan 2015 10:59:17
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2014-9308

Summary

Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin before 3.0.9 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in products/banners/.

Vulnerable Systems

Application

  • Wpeasycart Wp Easycart 3.0.8


References

CONFIRM - https://wordpress.org/plugins/wp-easycart/changelog/

BID - 71983

EXPLOIT-DB - 35730

MISC - http://security.szurek.pl/wordpress-shopping-cart-304-unrestricted-file-upload.html

MISC - http://packetstormsecurity.com/files/129875/WordPress-Shopping-Cart-3.0.4-Unrestricted-File-Upload.html

OSVDB - 116806


Last Updated: 27 May 2016 11:07:33