Home > Content Management, File Inclusion > WordPress Asset Manager Plugin Arbitrary File Upload

WordPress Asset Manager Plugin Arbitrary File Upload

June 30th, 2012

Application: WordPress
Affected Version: version 0.2 and other versions.
Vendor’s URL: Asset Manager Plugin
Bug Type: File Upload
Risk Level: Critical

Solution:
Restrict access to the wp-content/plugins/asset-manager/upload.php file (e.g. via .htaccess).

Content Management, File Inclusion

Comments are closed.