Contact Us
SECURITY BLOG SECURITY DASHBOARD PARTNERS PRODUCTS JOBS SERVICES COMPANY HOME
Network Security Consulting Advisories Article

WordPress HTML5 AV Manager Plugin 'custom.php' Arbitrary File Upload Vulnerability

http://www.securityfocus.com/bid/53804

Security Info

Bugtraq ID: 53804
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Jun 05 2012 12:00AM
Updated: Jun 05 2012 12:00AM
Credit: Sammy FORGIT
Vulnerable: WordPress HTML5 AV Manager 0.2.7
Not Vulnerable:

Security Discussion

The HTML5 AV Manager plug-in for WordPress is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.

An attacker can exploit this vulnerability to upload arbitrary PHP code and run it in the context of the Web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.

HTML5 AV Manager 0.2.7 is vulnerable; other versions may also be affected.

Proof of Concept and Security Exploits

Attackers can use a browser to exploit this issue.

The following exploit is available:

Security Solution(s)

Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com.

Security References(s)

References:

Contact Us

Security Penetration Testing

Security Questions

Security Dashboard

Emagined Security Blog featuring Dr. Eugene Schultz
Site Updated May 25, 2013
©2000-2013 Emagined Security
All Rights Reserved

Secure Web Programming
by Vizual Services