WordPress Gmedia Gallery plug-in Arbitrary File Upload Vulnerability
Release date: 2014-08-02
Updated on:
Affected Systems:
WordPress Gmedia Gallery 1.2.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 69014
WordPress Gmedia Gallery is a multi-media library for creating libraries and managing files.
Gmedia Gallery 1.2.1 and other versions do not effectively filter user input. There is a security vulnerability in implementation. Attackers can exploit this vulnerability to upload arbitrary files to affected computers, attackers can execute arbitrary code in the context of the affected application.
<* Source: fig
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://wordpress.org/plugins/grand-media/
This article permanently updates the link address: