Vulnerabilities > CVE-2008-6811 - Unspecified vulnerability in Instinct E-Commerce Plugin

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
instinct
wordpress
exploit available

Summary

Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/plugins/wp-shopping-cart/.

Vulnerable Configurations

Part Description Count
Application
Instinct
1
Application
Wordpress
1

Exploit-Db

descriptionWordpress Plugin e-Commerce <= 3.4 Arbitrary File Upload Exploit. CVE-2008-6811. Webapps exploit for php platform
fileexploits/php/webapps/6867.pl
idEDB-ID:6867
last seen2016-02-01
modified2008-10-29
platformphp
port
published2008-10-29
reportert0pP8uZz
sourcehttps://www.exploit-db.com/download/6867/
titleWordPress Plugin e-Commerce <= 3.4 - Arbitrary File Upload Exploit
typewebapps