Vulnerable Systems:
* Dailyedition-mouss Theme for WordPress
Dailyedition-mouss Theme for WordPress contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the thumb.php script does not properly verify or sanitize user-uploaded files passed via the 'src' parameter. By uploading a .php file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script with the privileges of the web server.
Disclosure Timeline:
Disclosure Date :2013-01-14
Discovery Date :2013-01-14