Ver todas as ameaças

CVE-2014-8739

Alvo: Não informado

Descrição

Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.

Software
Não informado
Tipo Software
Core
CVE
CVE-2014-8739
Tags
Nâo informado
Data de publicação
08/02/2020
Última atualização
08/12/2024
Pontuação em CVSS 3.0
9.8
Crítico
Rolar para cima