CVE-2014-8739
CRITICALEPSS 100th pctlDescription
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.
CVSS v3 Vector
Exploitability
Impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploit Intelligence
Very high risk: more likely to be exploited than 100% of all known CVEs.
References
- http://osvdb.org/show/osvdb/113669
- http://osvdb.org/show/osvdb/113673
- http://www.openwall.com/lists/oss-security/2014/11/11/4
- http://www.openwall.com/lists/oss-security/2014/11/11/5
- http://www.openwall.com/lists/oss-security/2014/11/13/3
- https://wordpress.org/plugins/sexy-contact-form/changelog/
- https://www.exploit-db.com/exploits/35057/
- https://www.exploit-db.com/exploits/36811/
Find and fix vulnerabilities across your fleet
TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
Start freeThis product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.