WordPress Theme Daily Deal - Arbitrary File Upload
Author: DevilScreaM type: webapps platform: php port: date_added: 2013-10-23 date_updated: 2015-11-25 verified: 1 codes: OSVDB-98924 tags: aliases: screenshot_url: application_url: raw file: 38811.txt
source: https://www.securityfocus.com/bid/63257/info The Daily Deal theme is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input. An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application. http://www.example.com/wp-content/themes/DailyDeal/monetize/upload/