Release date:
Updated on:
Affected Systems:
WordPress
Description:
--------------------------------------------------------------------------------
Bugtraq id: 63768
WordPress is a blog platform developed in PHP. you can build your own website on servers that support PHP and MySQL databases.
Multiple themes of WordPress have a Remote File Upload Vulnerability in the implementation of the upload-handler.php, attackers can exploit this vulnerability to upload arbitrary files to the affected computer, resulting in arbitrary code execution.
<* Source: DevilScreaM
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/wp-content/themes/amplus/functions/upload-handler.php
Http://www.example.com/wp-content/themes/dimension/library/includes/upload-handler.php
Http://www.example.com/wp-content/themes/euclid/functions/upload-handler.php
Http://www.example.com/wp-content/themes/euclid_v1.x.x/functions/upload-handler.php
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://wordpress.org/