Wordpress NextGEN Gallery Arbitrary File Upload Vulnerability
Release date:
Updated on:
Affected Systems:
WordPress NextGEN Gallery Plugin 2.x
Description:
--------------------------------------------------------------------------------
WordPress is a free forum Blog system.
NextGEN Gallery plugin for WordPress 2.0.65 and earlier versions do not correctly verify the mime type of the image file, which can lead to the upload and execution of arbitrary PHP code. To successfully exploit this vulnerability, the "Add gallery/Upload images" permission is required.
<* Source: SANTHO
Link: http://secunia.com/advisories/59647/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://wordpress.org/plugins/nextgen-gallery/changelog/
Http://packetstormsecurity.com/files/127340/WordPress-NextGEN-Gallery-2.0.63-Shell-Upload.html
This article permanently updates the link address: