CVE-2011-5051
published 2012-01-04CVE-2011-5051: Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by…
PriorityP348high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.25%
89.8th percentile
Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension using (1) uploadify/upload_admin_avatar.php or (2) uploadify/upload_profile_avatar.php, then accessing it via a direct request to the file in an unspecified directory inside the webroot.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wpsymposium | wp_symposium | <= 11.12.08 | — |
| wpsymposium | wp_symposium | — | — |
| wpsymposium | wp_symposium | — | — |
| wpsymposium | wp_symposium | — | — |
| wpsymposium | wp_symposium | — | — |
| wpsymposium | wp_symposium | — | — |
| wpsymposium | wp_symposium | — | — |
| wpsymposium | wp_symposium | — | — |
| wpsymposium | wp_symposium | — | — |
| wpsymposium | wp_symposium | — | — |
| wpsymposium | wp_symposium | — | — |
| wpsymposium | wp_symposium | — | — |
| wpsymposium | wp_symposium | — | — |
| wpsymposium | wp_symposium | — | — |
| wpsymposium | wp_symposium | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/78041http://osvdb.org/78042http://secunia.com/advisories/46097http://secunia.com/secunia_research/2011-91/https://exchange.xforce.ibmcloud.com/vulnerabilities/72012https://wpsymposium-trac.sourcerepo.com/wpsymposium_trac/ticket/265http://osvdb.org/78041http://osvdb.org/78042http://secunia.com/advisories/46097http://secunia.com/secunia_research/2011-91/https://exchange.xforce.ibmcloud.com/vulnerabilities/72012https://wpsymposium-trac.sourcerepo.com/wpsymposium_trac/ticket/265
2012-01-04
Published