The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/47995 | vdb entry |
http://secunia.com/advisories/49138 | third party advisory |
http://wordpress.org/news/2011/05/wordpress-3-1-3/ | patch |
http://www.debian.org/security/2012/dsa-2470 | vendor advisory |