Vulnerabilities > CVE-2015-4133 - Unspecified vulnerability in Reflex Gallery Project Reflex Gallery

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
reflex-gallery-project
exploit available
metasploit

Summary

Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory. <a href="http://cwe.mitre.org/data/definitions/434.html">CWE-434: Unrestricted Upload of File with Dangerous Type</a>

Exploit-Db

descriptionWordpress Reflex Gallery Upload Vulnerability. Remote exploit for php platform
fileexploits/php/remote/36809.rb
idEDB-ID:36809
last seen2016-02-04
modified2015-04-21
platformphp
port80
published2015-04-21
reportermetasploit
sourcehttps://www.exploit-db.com/download/36809/
titleWordPress Reflex Gallery Upload Vulnerability
typeremote

Metasploit