[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2019-8943 -- wordpress

ID: oval:org.secpod.oval:def:2000348Date: (C)2019-04-23   (M)2021-06-06
Class: VULNERABILITYFamily: unix




WordPress through 5.0.3 allows Path Traversal in wp_crop_image. An attacker can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.

Platform:
Debian 8.x
Debian 9.x
Product:
wordpress
Reference:
CVE-2019-8943
CVE    1
CVE-2019-8943
CPE    3
cpe:/a:wordpress:wordpress
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies