The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code.
References
Link Resource
http://www.vapidlabs.com/advisory.php?v=117 Exploit Third Party Advisory
https://www.openwall.com/lists/oss-security/2015/04/01/2 Exploit Mailing List Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:16:02

Updated: 2022-10-03T16:16:02

Reserved: 2022-10-03T00:00:00


Link: CVE-2015-9272

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-10-05T06:29:00.780

Modified: 2018-11-23T19:16:34.400


Link: CVE-2015-9272

JSON object: View

cve-icon Redhat Information

No data.

CWE