Vulnerable Systems:
* Fine Uploader Plugin for WordPress
Fine Uploader Plugin for WordPress contains a flaw that allows a remote user to execute arbitrary code. This flaw exists because the program does not properly verify or sanitize user-uploaded files. By uploading a file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script with the privileges of the web server.
Vendor Status:
Currently, We are not aware of any updates from the vendor
Disclosure Timeline:
Disclosure Date :2013-01-04
Exploit Publish Date: 2013-01-04