mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-06-20 09:50:49 +00:00
add WordPress Plugin Mailpress 4.5.2 RCE
This commit is contained in:
parent
e8865f7de9
commit
9d72c8537b
BIN
WordPress/Mailpress/WordPress_Plugin_Mailpress_4.5.2_RCE.gif
Normal file
BIN
WordPress/Mailpress/WordPress_Plugin_Mailpress_4.5.2_RCE.gif
Normal file
Binary file not shown.
After Width: | Height: | Size: 622 KiB |
11
WordPress/Mailpress/WordPress_Plugin_Mailpress_4.5.2_RCE.md
Normal file
11
WordPress/Mailpress/WordPress_Plugin_Mailpress_4.5.2_RCE.md
Normal file
@ -0,0 +1,11 @@
|
||||
# WordPress Plugin Mailpress 4.5.2 RCE
|
||||
|
||||
In the WordPress Mailpress Plugin, the subject parameter in the iview function in the mailpress/mp-includes/class/MP_Actions.class.php file is not filtered, and pass to do_eval function, leading to remote code execution.
|
||||
|
||||
**Affected version**: WordPress Plugin Mailpress <= 4.5.2
|
||||
|
||||
**FOFA query rule**: [app="WordPress"](https://fofa.so/result?qbase64=YXBwPSJXb3JkUHJlc3Mi)
|
||||
|
||||
# Demo
|
||||
|
||||

|
Loading…
x
Reference in New Issue
Block a user