Enable Media Replace, 998cd782c633045e5da1cdac6b7b7cd2ce8eb0d2
- CVE, Research URL
- Home page URL
- Application
- Published on
- Feb 09, 2011
- Research Description
- Enable Media Replace [enable-media-replace] < 2.4 (closed) WordPress Enable Media Replace Plugin - Multiple Vulnerabilities In general, impact of this plugin is information retrieval and manipulation, arbitrary code execution. More details: there exist multiple vulnerabilities in Enable Media Replace plugin for WordPress: 1. Users can perform SQL injection attacks against the plugin. 2. Users can upload arbitrary files (for the example, PHP files) to retrieve or change important information in the SQL database.
- Affected versions
-
max 2.4.
- Status
-
vulnerable