CVE-2015-1784: Malicious File Upload
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2015-1784.
What is the severity of CVE-2015-1784?
The severity of CVE-2015-1784 is high with a severity value of 8.8.
What is affected by CVE-2015-1784?
The nextgen-gallery WordPress plugin before version 2.0.77.3 is affected by CVE-2015-1784.
How can an attacker exploit CVE-2015-1784?
An attacker can exploit CVE-2015-1784 by uploading malicious files and making unwanted HTTP requests.
Are there any references available for CVE-2015-1784?
Yes, you can find references for CVE-2015-1784 at the following links: [Reference 1](https://blog.nettitude.com/uk/crsf-and-unsafe-arbitrary-file-upload-in-nextgen-gallery-plugin-for-wordpress), [Reference 2](https://wpscan.com/vulnerability/c894727a-b779-4583-a860-13c2c27275d4).