CVE-2012-3575
Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/rbxslider.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 15.42% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- rbx gallery/rbx gallery
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/49463Vendor Advisory
- http://www.exploit-db.com/exploits/19019
- http://www.opensyscom.fr/Actualites/wordpress-plugins-rbx-gallery-multiple-arbitrary-file-upload-vulnerability.htmlExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76170
- http://secunia.com/advisories/49463Vendor Advisory
- http://www.exploit-db.com/exploits/19019
- http://www.opensyscom.fr/Actualites/wordpress-plugins-rbx-gallery-multiple-arbitrary-file-upload-vulnerability.htmlExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76170
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.