CVE-2013-5962

UnknownEPSS 14.77%

Last modified

CVE-2013-5962 is a vulnerability of currently unknown severity. Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.. EPSS estimates a 14.77% chance of exploitation in the next 30 days.

Description

Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.

Metrics

EPSS Probability
14.77%

96.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersionsUpdate
EnvatoComplete Gallery Manager Plugin<= 3.3.3Rev39177
EnvatoComplete Gallery Manager Plugin1.0.0Rev25273
EnvatoComplete Gallery Manager Plugin1.0.1Rev25421
EnvatoComplete Gallery Manager Plugin1.0.2Rev25487
EnvatoComplete Gallery Manager Plugin2.0.0Rev27524
EnvatoComplete Gallery Manager Plugin2.0.1Rev27876
EnvatoComplete Gallery Manager Plugin2.0.2Rev28693
EnvatoComplete Gallery Manager Plugin2.0.3Rev28734
EnvatoComplete Gallery Manager Plugin3.0.0Rev29469
EnvatoComplete Gallery Manager Plugin3.0.1Rev29536
EnvatoComplete Gallery Manager Plugin3.1.0Rev30003
EnvatoComplete Gallery Manager Plugin3.1.1Rev30900
EnvatoComplete Gallery Manager Plugin3.2.0Rev31030
EnvatoComplete Gallery Manager Plugin3.2.1Rev33197
EnvatoComplete Gallery Manager Plugin3.2.2Rev33971
EnvatoComplete Gallery Manager Plugin3.2.3Rev34390
EnvatoComplete Gallery Manager Plugin3.2.4Rev34757
EnvatoComplete Gallery Manager Plugin3.2.5Rev34942
EnvatoComplete Gallery Manager Plugin3.2.6Rev36235
EnvatoComplete Gallery Manager Plugin3.2.7Rev36257
EnvatoComplete Gallery Manager Plugin3.2.8Rev36369
EnvatoComplete Gallery Manager Plugin3.3.0Rev36620
EnvatoComplete Gallery Manager Plugin3.3.1Rev38906
EnvatoComplete Gallery Manager Plugin3.3.2Rev39009

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-5962?
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.
How severe is CVE-2013-5962?
Severity scoring for CVE-2013-5962 is pending analysis. The EPSS model estimates a 14.77% probability of exploitation in the next 30 days.
How do I fix CVE-2013-5962?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-5962?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST