漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
WordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE
Vulnerability Description
WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP shells through the Products tab custom file field and access them via the upcp-product-file-uploads directory to execute arbitrary code on the server.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
授权机制不正确
Vulnerability Title
etoilewebdesign ultimate product catalog 授权问题漏洞
Vulnerability Description
etoilewebdesign ultimate product catalog是etoilewebdesign个人开发者开源的一套产品目录管理插件。 etoilewebdesign ultimate product catalog 3.8.6版本存在授权问题漏洞,该漏洞源于自定义字段功能利用不当,允许已认证用户上传恶意文件,攻击者可通过Products标签自定义文件字段上传PHP shells并通过upcp-product-file-uploads目录访问,从而在服务器上执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A