

In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved.

Source: CVE-2013-1916

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다