Release date:
Updated on:
Affected Systems:
WordPress WP-Filebase Download Manager 0.3.0.03
Description:
--------------------------------------------------------------------------------
WP-Filebase Download Manager is an advanced File Download Manager for WordPress.
WP-Filebase Download Manager 0.3.0.03 and other versions do not properly filter the input in filename when uploading files. They are used to call classes/Admin. "exec ()" in php, which can be exploited by attackers to inject and execute arbitrary shell commands through specially crafted http post requests. Successful exploitation of this vulnerability requires the permission to upload files.
<* Source: vendor
Link: http://secunia.com/advisories/57456/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://wordpress.org/plugins/wp-filebase/
Http://wordpress.org/plugins/wp-filebase/changelog/