Vulnerabilities > CVE-2015-2825 - Unspecified vulnerability in Simple ADS Manager Project Simple ADS Manager 2.5.94
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN simple-ads-manager-project
exploit available
Summary
Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the path parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
D2sec
name | WordPress Simple Ads Manager File Upload |
url | http://www.d2sec.com/exploits/wordpress_simple_ads_manager_file_upload.html |
Exploit-Db
description | Wordpress Simple Ads Manager 2.5.94 - Arbitrary File Upload. CVE-2015-2825. Webapps exploit for php platform |
file | exploits/php/webapps/36614.txt |
id | EDB-ID:36614 |
last seen | 2016-02-04 |
modified | 2015-04-02 |
platform | php |
port | 80 |
published | 2015-04-02 |
reporter | ITAS Team |
source | https://www.exploit-db.com/download/36614/ |
title | WordPress Simple Ads Manager 2.5.94 - Arbitrary File Upload |
type | webapps |
Packetstorm
data source | https://packetstormsecurity.com/files/download/131282/wpsam-upload.txt |
id | PACKETSTORM:131282 |
last seen | 2016-12-05 |
published | 2015-04-03 |
reporter | Tien Tran Dinh |
source | https://packetstormsecurity.com/files/131282/WordPress-Simple-Ads-Manager-2.5.94-File-Upload.html |
title | WordPress Simple Ads Manager 2.5.94 File Upload |
References
- http://packetstormsecurity.com/files/131282/WordPress-Simple-Ads-Manager-2.5.94-File-Upload.html
- http://packetstormsecurity.com/files/131282/WordPress-Simple-Ads-Manager-2.5.94-File-Upload.html
- http://seclists.org/fulldisclosure/2015/Apr/8
- http://seclists.org/fulldisclosure/2015/Apr/8
- http://www.itas.vn/news/ITAS-Team-found-out-multiple-critical-vulnerabilities-in-Hakin9-IT-Security-Magazine-78.html
- http://www.itas.vn/news/ITAS-Team-found-out-multiple-critical-vulnerabilities-in-Hakin9-IT-Security-Magazine-78.html
- https://wordpress.org/plugins/simple-ads-manager/changelog/
- https://wordpress.org/plugins/simple-ads-manager/changelog/
- https://www.exploit-db.com/exploits/36614/
- https://www.exploit-db.com/exploits/36614/