Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles query parameter is set, allows remote attackers to execute arbitrary code by uploading a file with a double extension, then accessing it via a direct request to the file in the uploads directory, as demonstrated by the .php.swp filename.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
InfiniteWP Admin Panel 代码注入漏洞
Vulnerability Description
InfiniteWP Admin Panel是美国InfiniteWP公司的一套免费的支持自托管多个WordPress管理平台,以及简化WordPress管理任务的管理面板软件。 InfiniteWP Admin Panel 2.4.4之前版本的uploadScript.php脚本中存在任意文件上传漏洞。当程序设置‘allWPFiles query’参数时,远程攻击者可通过发送直接的请求,上传并访问带有双重扩展的文件利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A