Affected System: WordPress SB Uploader 3.9 Description: SB Uploader is a simple plug-in that uploads images and attaches them to the content. WordPress SB Uploader has a security vulnerability. wp-content/plugins/sb-uploader/sb_uploader.php does not verify the uploaded files. By submitting malicious PHP scripts, any PHP code can be executed. <* Source: edevil aXe link: http://packetstormsecurity.com/files/119159/wpsbuploader39-shell.txt http://www.securelist.com/en/advisories/48076*> Test method: warning the following procedures (methods) may be offensive, only for security research and teaching. Users are at your own risk! Edevil aXe () provides the following test methods: p0c: www.2cto.com/wp-content/uploads/2012/12/cOol.htmTemporary solution:If you cannot install or upgrade the patch immediately, NSFOCUS recommends that you take the following measures to reduce the threat: * disable the WordPress SB Uploader plug-in vendor patch: WordPress --------- currently, the vendor has not provided the patch or upgrade program, we recommend that users who use this software stay tuned to the vendor's homepage for the latest version: http://wordpress.org/extend/plugins/sb-uploader/