Give some description

patch-1
Noam Rathaus 2021-04-27 14:02:08 +03:00
parent 1aca402bf6
commit f55bb45e75
1 changed files with 2 additions and 0 deletions

View File

@ -5,6 +5,8 @@ info:
author: princechaddha
severity: critical
reference: https://wpscan.com/vulnerability/10192
description: |
The Simple File List WordPress plugin was found to be vulnerable to an unauthenticated arbitrary file upload leading to remote code execution. The Python exploit first uploads a file containing PHP code but with a png image file extension. A second request is sent to move (rename) the png file to a PHP file.
tags: wordpress,wp-plugin,rce
requests: