wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script's pathname to active_plugins.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2008-12-19 18:30
Updated : 2025-04-09 00:30
NVD link : CVE-2008-5695
Mitre link : CVE-2008-5695
CVE.ORG link : CVE-2008-5695
JSON object : View
Products Affected
wordpress
- wordpress_mu
- wordpress
CWE
CWE-20
Improper Input Validation