wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script's pathname to active_plugins.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T11:04:44.132Z
Reserved: 2008-12-19T00:00:00
Link: CVE-2008-5695
No data.
Status : Deferred
Published: 2008-12-19T18:30:00.467
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-5695
No data.
OpenCVE Enrichment
No data.
Weaknesses