WordPress 2.8.5 Unrestricted File Upload Arbitrary PHP Code Execution
WordPress 2.8.5 Unrestricted File Upload Arbitrary PHP Code Execution已关闭评论
漏洞分析就不说了,下面我们来看下漏洞利用吧! Browser is enough to replicate this issue. Simply log in to your wordpress blog as a low privileged user or admin. Create a new post and use the media file upload feature to upload a file: test-image.php.jpg containing the ReadMore