WordPress Simple File List...

- AV AC AU C I A
发布: 2020-11-25
修订: 2024-12-11

This Metasploit module exploits WordPress Simple File List plugin versions prior to 4.2.3, which allows remote unauthenticated attackers to upload files within a controlled list of extensions. However, the rename function does not conform to the file extension restrictions, thus allowing arbitrary PHP code to be uploaded first as a png then renamed to php and executed.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息