Security Advisory

CVE-2014-9521

7.5

Vulnerability Description

Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles query parameter is set, allows remote attackers to execute arbitrary code by uploading a file with a double extension, then accessing it via a direct request to the file in the uploads directory, as demonstrated by the .php.swp filename.
Published Date January 5, 2015
Official Source NIST NVD Advisory