[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2019-8942 -- wordpress

ID: oval:org.secpod.oval:def:1900765Date: (C)2019-06-14   (M)2023-12-20
Class: VULNERABILITYFamily: unix




WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.

Platform:
Ubuntu 16.04
Ubuntu 18.04
Debian 8.x
Debian 9.x
Debian 10.x
Debian 11.x
Debian 12.x
Product:
wordpress
Reference:
CVE-2019-8942
CVE    1
CVE-2019-8942
CPE    5
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/o:ubuntu:ubuntu_linux:18.04
cpe:/o:ubuntu:ubuntu_linux:14.04
cpe:/a:wordpress:wordpress
...

© SecPod Technologies