Vulnerabilities > Envato > Complete Gallery Manager Plugin > 3.0.1

DATE CVE VULNERABILITY TITLE RISK
2013-09-30 CVE-2013-5962 Unspecified vulnerability in Envato Complete Gallery Manager Plugin
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.
network
high complexity
envato
5.1