LB Mixed Slideshow for WordPress <= 1.0 - Arbitrary File Upload
critical
The "LB Mixed Slideshow for WordPress" plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions up to, and including, 1.0. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code ex...
- CVSS:
- 9.8
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 18, 2012
LB Mixed Slideshow for WordPress [lb-mixed-slideshow] < 1.1 (closed)
unknown
LB Mixed Slideshow plugin's "upload.php" is prone to an arbitrary file upload vulnerability. Restricted access to this script is not properly realized. In that way an attacker can to upload files containing malicious PHP code and run it in the context of the web server process. Other attacks are also possible.
Updat...
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jun 18, 2012
LB Mixed Slideshow for WordPress [lb-mixed-slideshow] <= 1.0 (unfixed)
unknown
The "LB Mixed Slideshow for WordPress" plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions up to, and including, 1.0. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code ex...
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 18, 2012
LB Mixed Slideshow for WordPress [lb-mixed-slideshow] <= 1.0 (unfixed + closed)
unknown
The lb-mixed-slideshow WordPress plugin was affected by an Arbitrary File Upload security vulnerability.
- Affected:
- up to 1.0
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database