CVE Database
/

CVE-2007-3543

Back to search

CVE-2007-3543

Published: Jul 3, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the _wp_attached_file metadata field; and then sending this file's content, along with its post_ID value, to (1) wp-app.php or (2) app.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

25794
third-party-advisory
x_refsource_SECUNIA
24642
vdb-entry
x_refsource_BID
37295
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now