Woopra Analytics Plugin < 1.4.3.2 - Remote Code Execution
critical
The Woopra Analytics Plugin for WordPress is vulnerable to Remote Code Execution in versions before 1.4.3.2 via the 'file' parameter in the ofc_upload_image.php file. This allows attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 1.4.3.2
- Fixed in:
- 1.4.3.2
- Disclosed:
- Oct 7, 2013
Various Affected Software (Various Versions) - Arbitrary File Upload
high
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 through 0.4.3, Woopra Analytics Plugin before 1.4.3.2, and possibly other products, when register_globals is enabled, allows remote authenticated users to execute arbitrary c...
- CVSS:
- 8.8
- Affected:
- up to 1.4.3.1
- Fixed in:
- 1.4.3.2
- Disclosed:
- Oct 21, 2009
CVE-2009-4140 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database