WPshop 2 – E-Commerce, 85bb2718-2228-4405-8b50-76995dbf6862
- CVE, Research URL
- Home page URL
- Application
- Published on
- -
- Research Description
- WPshop 2 – E-Commerce [wpshop] < 1.3.9.6 Wpshop - eCommerce <= 1.3.9.5 - Arbitrary File Upload The script 'includes/ajax.php' allows execution of various actions by anonymous users. The action name is provided in the 'elementCode' parameter. One of these actions is named 'ajaxUpload'. This function allows for upload of arbitrary files, due to lack of sanitation of user input.
- Affected versions
-
max 1.3.9.6.
- Status
-
vulnerable