CVE-2014-5460
Last modified
CVE-2014-5460 is a vulnerability of currently unknown severity. Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.. EPSS estimates a 70.89% chance of exploitation in the next 30 days.
Description
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tribulant | Tibulant Slideshow Gallery | <= 1.4.6 |
| Tribulant | Tibulant Slideshow Gallery | 1.4 |
| Tribulant | Tibulant Slideshow Gallery | 1.4.1 |
| Tribulant | Tibulant Slideshow Gallery | 1.4.2 |
| Tribulant | Tibulant Slideshow Gallery | 1.4.3 |
| Tribulant | Tibulant Slideshow Gallery | 1.4.4 |
| Tribulant | Tibulant Slideshow Gallery | 1.4.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-5460?
How severe is CVE-2014-5460?
How do I fix CVE-2014-5460?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-5454Unrestricted file upload vulnerability in the image upload m…
- CVE-2014-5455Unquoted Windows search path vulnerability in the ptservice …5.3
- CVE-2014-5456Cross-site scripting (XSS) vulnerability in the Social Stats…
- CVE-2014-5457QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS…
- CVE-2014-5458SQL injection vulnerability in sqrl_verify.php in php-sqrl a…
- CVE-2014-5459The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0…
- CVE-2014-5461Buffer overflow in the vararg functions in ldo.c in Lua 5.1 …
- CVE-2014-5462Multiple SQL injection vulnerabilities in OpenEMR 4.1.2 (Pat…
- CVE-2014-5464Cross-site scripting (XSS) vulnerability in the nDPI traffic…
- CVE-2014-5465Directory traversal vulnerability in force-download.php in t…
- CVE-2014-5466Cross-site scripting (XSS) vulnerability in the Dashboard in…
- CVE-2014-5468A File Inclusion vulnerability exists in Railo 4.2.1 and ear…8.8
Are you affected by CVE-2014-5460?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
