WordPress WP-DownloadManager Plugin...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

漏洞文件: `download-add.php` 漏洞代码: if( ! empty( $_POST['do'] ) ) { check_admin_referer('wp-downloadmanager_add-file'); // Decide What To Do switch( $_POST['do'] ) { // Add File case __('Add File', 'wp-downloadmanager'): $file_type = ! empty( $_POST['file_type']) ? intval( $_POST['file_type'] ) : 0; switch($file_type) { case 0: $file = ! empty( $_POST['file'] ) ? addslashes( wp_kses_post( trim( $_POST['file'] ) ) ) : ''; $file = download_rename_file($file_path, $file); $file_size = filesize($file_path.$file); break; case 1: if($_FILES['file_upload']['size'] > get_max_upload_size()) { $text = '<p style="color: red;">'.sprintf(__('File Size Too Large. Maximum Size Is %s', 'wp-downloadmanager'), format_filesize(get_max_upload_size())).'</p>'; break; } else { if(is_uploaded_file($_FILES['file_upload']['tmp_name'])) { $file_upload_to = ! empty( $_POST['file_upload_to'] ) ? $_POST['file_upload_to'] : ''; if( $file_upload_to !== '/' ) { $file_upload_to = $file_upload_to . '/'; }...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息