Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

WordPress < 2.2.1 'wp_attached_file' Unrestricted File Upload

Medium

Synopsis

The remote host is vulnerable to a script injection attack.

Description

The version of WordPress installed on the remote host is vulnerable to a file upload attack. An attacker exploiting this flaw would only need to be able to send custom queries to the 'wp-app.php' or 'app.php' script. Successful exploitation would result in the attacker uploading arbitrary code that could then be executed with the privileges of the web server.

Solution

Upgrade to WordPress 2.2.1, or later.