cve/2015/CVE-2015-9228.md
2024-06-18 02:51:15 +02:00

867 B

CVE-2015-9228

Description

In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.

POC

Reference

Github

No PoCs found on GitHub currently.