Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script's pathname to active_plugins.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress 输入验证错误漏洞
Vulnerability Description
WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress MU 1.3.2之前的版本和WordPress 2.3.2 及其早期版本的wp-admin/options.php存在输入验证错误漏洞,该漏洞源于没有适当地验证对更新选项的请求,这会允许具有管理选项和上传文件能力的远程验证用户通过上传一个PHP脚本并添加该脚本的路径名到active_plugins中,以执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A