CVE-2015-9228: Malicious File Upload
Published Sep 12, 2017
·Updated
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
Affected Software
70 affected components
Imagely Nextgen Gallery Wordpress=1.5.0
Imagely Nextgen Gallery Wordpress=1.5.1
Imagely Nextgen Gallery Wordpress=1.5.2
Imagely Nextgen Gallery Wordpress=1.5.3
Imagely Nextgen Gallery Wordpress=1.5.4
Imagely Nextgen Gallery Wordpress=1.5.5
Imagely Nextgen Gallery Wordpress=1.6.0
Imagely Nextgen Gallery Wordpress=1.6.1
Imagely Nextgen Gallery Wordpress=1.6.2
Imagely Nextgen Gallery Wordpress=1.7.0
Imagely Nextgen Gallery Wordpress=1.7.1
Imagely Nextgen Gallery Wordpress=1.7.2
Imagely Nextgen Gallery Wordpress=1.7.3
Imagely Nextgen Gallery Wordpress=1.7.4
Imagely Nextgen Gallery Wordpress=1.8.0
Imagely Nextgen Gallery Wordpress=1.8.1
Imagely Nextgen Gallery Wordpress=1.8.2
Imagely Nextgen Gallery Wordpress=1.8.3
Imagely Nextgen Gallery Wordpress=1.8.4
Imagely Nextgen Gallery Wordpress=1.9.0
Imagely Nextgen Gallery Wordpress=1.9.1
Imagely Nextgen Gallery Wordpress=1.9.2
Imagely Nextgen Gallery Wordpress=1.9.3
Imagely Nextgen Gallery Wordpress=1.9.5
Imagely Nextgen Gallery Wordpress=1.9.6
Imagely Nextgen Gallery Wordpress=1.9.7
Imagely Nextgen Gallery Wordpress=1.9.8
Imagely Nextgen Gallery Wordpress=1.9.10
Imagely Nextgen Gallery Wordpress=1.9.11
Imagely Nextgen Gallery Wordpress=1.9.12
Imagely Nextgen Gallery Wordpress=1.9.13
Imagely Nextgen Gallery Wordpress=2.0
Imagely Nextgen Gallery Wordpress=2.0.7
Imagely Nextgen Gallery Wordpress=2.0.11
Imagely Nextgen Gallery Wordpress=2.0.14
Imagely Nextgen Gallery Wordpress=2.0.17
Imagely Nextgen Gallery Wordpress=2.0.21
Imagely Nextgen Gallery Wordpress=2.0.23
Imagely Nextgen Gallery Wordpress=2.0.25
Imagely Nextgen Gallery Wordpress=2.0.27
Imagely Nextgen Gallery Wordpress=2.0.30
Imagely Nextgen Gallery Wordpress=2.0.31
Imagely Nextgen Gallery Wordpress=2.0.33
Imagely Nextgen Gallery Wordpress=2.0.40
Imagely Nextgen Gallery Wordpress=2.0.57
Imagely Nextgen Gallery Wordpress=2.0.58
Imagely Nextgen Gallery Wordpress=2.0.59
Imagely Nextgen Gallery Wordpress=2.0.61
Imagely Nextgen Gallery Wordpress=2.0.63
Imagely Nextgen Gallery Wordpress=2.0.65
Imagely Nextgen Gallery Wordpress=2.0.66
Imagely Nextgen Gallery Wordpress=2.0.66.16
Imagely Nextgen Gallery Wordpress=2.0.66.17
Imagely Nextgen Gallery Wordpress=2.0.66.26
Imagely Nextgen Gallery Wordpress=2.0.66.27
Imagely Nextgen Gallery Wordpress=2.0.66.29
Imagely Nextgen Gallery Wordpress=2.0.66.31
Imagely Nextgen Gallery Wordpress=2.0.66.33
Imagely Nextgen Gallery Wordpress=2.0.71
Imagely Nextgen Gallery Wordpress=2.0.74
Imagely Nextgen Gallery Wordpress=2.0.76
Imagely Nextgen Gallery Wordpress=2.0.77
Imagely Nextgen Gallery Wordpress=2.0.78
Imagely Nextgen Gallery Wordpress=2.0.78.1
Imagely Nextgen Gallery Wordpress=2.0.79
Imagely Nextgen Gallery Wordpress=2.1.0
Imagely Nextgen Gallery Wordpress=2.1.2
Imagely Nextgen Gallery Wordpress=2.1.7
Imagely Nextgen Gallery Wordpress=2.1.9
Imagely Nextgen Gallery Wordpress=2.1.10
Event History
Sep 12, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9228?
CVE-2015-9228 has a high severity level due to the potential for remote code execution through unrestricted file upload.
2
How do I fix CVE-2015-9228?
To fix CVE-2015-9228, update the Photocrati NextGEN Gallery plugin to version 2.1.11 or later.
3
What types of files are affected by CVE-2015-9228?
CVE-2015-9228 allows the upload of PHP files disguised as JPEG images due to improper validation.
4
Is my site vulnerable to CVE-2015-9228?
If you're using Photocrati NextGEN Gallery plugin version 2.1.10 or earlier, your site is vulnerable to CVE-2015-9228.
5
What systems are impacted by CVE-2015-9228?
CVE-2015-9228 affects multiple versions of the NextGEN Gallery plugin for WordPress, specifically 2.1.10 and earlier.