CVE-2013-5962
published 2013-09-30CVE-2013-5962: Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote…
PriorityP354medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EXPLOIT
EPSS
14.77%
96.3th percentile
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| envato | complete_gallery_manager_plugin | <= 3.3.3 | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
| envato | complete_gallery_manager_plugin | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9vx7-4qrw-wfw5: Unrestricted file upload vulnerability in frames/upload-images
ghsa_unreviewed·2022-05-17
CVE-2013-5962 [MEDIUM] GHSA-9vx7-4qrw-wfw5: Unrestricted file upload vulnerability in frames/upload-images
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.
Cisco
Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities
vendor_cisco
CVE-2012-5962 Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities
CVE-2012-5962: Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities
The Portable Software Developer Kit (SDK) for Universal Plug-n-Play (UPnP) Devices contains a libupnp library, originally known as the Intel SDK for UPnP Devices, which is vulnerable to multiple stack-based buffer overflows when handling malicious Simple Service Discovery Protocol (SSDP) requests. This library is used in several vendor network devices, in addition to media streaming and file sharing applications. These vulnerabilities were disclosed on January 29th, 2013 in a CERT Vulnerability Note, VU#922681, which can be viewed at http://www.kb.cert.org/vuls/id/922681 . Cisco is currently evaluating products for possible exposure to these vulnerabilities. This advisory is available at the following lin
No detection rules found.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2013-09/0090.htmlhttp://codecanyon.net/item/complete-gallery-manager-for-wordpress/2418606http://packetstormsecurity.com/files/123303http://secunia.com/advisories/54894http://www.exploit-db.com/exploits/28377http://www.vulnerability-lab.com/get_content.php?id=1080https://exchange.xforce.ibmcloud.com/vulnerabilities/87172http://archives.neohapsis.com/archives/bugtraq/2013-09/0090.htmlhttp://codecanyon.net/item/complete-gallery-manager-for-wordpress/2418606http://packetstormsecurity.com/files/123303http://secunia.com/advisories/54894http://www.exploit-db.com/exploits/28377http://www.vulnerability-lab.com/get_content.php?id=1080https://exchange.xforce.ibmcloud.com/vulnerabilities/87172
2013-09-30
Published