Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the _wp_attached_file metadata field; and then sending this file's content, along with its post_ID value, to (1) wp-app.php or (2) app.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress自定义字段任意文件上传漏洞
Vulnerability Description
"WordPress是一款免费的论坛Blog系统。 WordPress处理用户提交的数据时存在漏洞,远程攻击者可能利用此漏洞非授权操作文件。 WordPress允许上传有限的文件附件组,其中名称、标题等以post_type=attachment存储到了wp_posts表中,而路径和其他文件属性以名为_wp_attached_file和_wp_attachment_metadata的特殊字段被存储到了wp_postmeta表中。 WordPress还允许在正常的张贴或页面中添加自定义字段,该自定义字段也被存
CVSS Information
N/A
Vulnerability Type
N/A