← العودة للجدول
CVE-2014-8739
CVE-2014-8739 — Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQ
📅 2020-02-08
🔴 Critical 🔥 Yes NVD Exploit Web CVSS 9.8

📋 الوصف الكامل

Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request

💻 الأنظمة المتأثرة

WordPress 6.5.x

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2014-8739

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2014-8739 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←