Vulnerability Description
The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code, a different vulnerability than CVE-2014-1905.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Videowhisper | Video Conference | 4.91.8 |
Related Weaknesses (CWE)
References
- http://www.vapidlabs.com/advisory.php?v=116ExploitThird Party Advisory
- http://www.vapidlabs.com/advisory.php?v=116ExploitThird Party Advisory
FAQ
What is CVE-2015-9271?
CVE-2015-9271 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are ...
How severe is CVE-2015-9271?
CVE-2015-9271 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-9271?
Check the references section above for vendor advisories and patch information. Affected products include: Videowhisper Video Conference.