cleantalk
Vulnerabilities and Security Researches

Enable Media Replace, 998cd782c633045e5da1cdac6b7b7cd2ce8eb0d2

Application

Enable Media Replace

Published on
Feb 09, 2011
Research Description
Enable Media Replace [enable-media-replace] < 2.4 (closed) WordPress Enable Media Replace Plugin - Multiple Vulnerabilities In general, impact of this plugin is information retrieval and manipulation, arbitrary code execution. More details: there exist multiple vulnerabilities in Enable Media Replace plugin for WordPress: 1. Users can perform SQL injection attacks against the plugin. 2. Users can upload arbitrary files (for the example, PHP files) to retrieve or change important information in the SQL database.
Affected versions
max 2.4.
Status
vulnerable