First published: Thu Jan 10 2008(Updated: )
Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress File Manager | =1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0222 is considered a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2008-0222, you should update the Wp-FileManager plugin to a patched version that addresses this vulnerability.
The impact of CVE-2008-0222 includes unauthorized file uploads and the execution of malicious PHP code on the server.
CVE-2008-0222 affects installations of the Wp-FileManager plugin version 1.2 for WordPress.
An attacker exploits CVE-2008-0222 by uploading arbitrary PHP files through the ajaxfilemanager.php script without sufficient restrictions.