CVE-2008-3362: Input Validation
Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the upfile parameter, then accessing it via a direct request to the file in wp-content/plugins/downloads-manager/upload/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3362?
CVE-2008-3362 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2008-3362?
To fix CVE-2008-3362, you should update the WP Downloads Manager module to a version that has patched this vulnerability.
What type of attack is associated with CVE-2008-3362?
CVE-2008-3362 is associated with unrestricted file upload attacks that allow arbitrary code execution.
What software is affected by CVE-2008-3362?
CVE-2008-3362 specifically affects version 0.2 of the WP Downloads Manager module for WordPress.
Can CVE-2008-3362 be exploited remotely?
Yes, CVE-2008-3362 can be exploited remotely by uploading malicious files through the vulnerable upload feature.