WordPress 2.8.5 Unrestricted File Upload Arbitrary PHP Code Execution

漏洞分析就不说了,下面我们来看下漏洞利用吧! Browser is enough to replicate this issue. Simply log in to your wordpress blog as a low privileged user or admin. Create a new post and use the media file upload feature to upload a file: test-image.php.jpg containing the ReadMore