Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress Photocrati NextGEN Gallery插件代码问题漏洞
Vulnerability Description
WordPress 插件是WordPress开源的一个应用插件。 WordPress Photocrati NextGEN Gallery插件2.1.10版本中的post-new.php文件存在代码问题漏洞。攻击者可借助‘name’参数利用该漏洞向服务器上传文件,获取root权限。
CVSS Information
N/A
Vulnerability Type
N/A