Advertisement






WordPress SB Uploader 4.9 Arbitrary File Upload Vulnerability

CVE Category Price Severity
CVE-2021-24196 CWE-434 Not disclosed High
Author Risk Exploitation Type Date
exploitalert team High Remote 2017-09-09
CPE
cpe:cpe:/a:wordpress:sb_uploader:4.9
CVSS EPSS EPSSP
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2017090056

Below is a copy:

 WordPress SB Uploader 4.9 Arbitrary File Upload Vulnerability# Exploit Title:  WordPress SB Uploader 4.9 Arbitrary File Upload Vulnerability
# Exploit Author: Dyar Sahdi
# http://www.facebook.com/Dyar.Sahdi.Linux
# Software Link: http://wordpress.org/extend/plugins/sb-uploader/
# Version: 3.9
# Category: webapps
# Tested on: [Windows 7] [Linux] [windows10]
# Google Dork : "inurl:plugins/sb-uploader"

=====================
Vulnerability : Arbitrary File Upload Vulnerability
=====================
Exploit Details :
=====================

1. Register
2. Login [Confirm your email then login]
3. Add a New post
4. Write title,body something what you want :)
5. Look at the Right slidbar " SB Uploader" panel and upload your file :)
6. Publish the post
7. You file is uploaded here : /wp/wp-content/uploads/2012/02/yourfile[.]ext

=====================
p0c: localhost/wp/wp-content/uploads/2012/12/cOol.htm

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum