← Back

CVE-2011-5051

nvd nist
Published: Jan 4, 2012Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension using (1) uploadify/upload_admin_avatar.php or (2) uploadify/upload_profile_avatar.php, then accessing it via a direct request to the file in an unspecified directory inside the webroot.

Affected (15)

1 product
Wp Symposium
Configuration A
15 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Wpsymposium
Up to 11.12.08
Version 11.10.15
Version 11.10.1
Version 11.10.22
Version 11.10.29
Version 11.10.8
Version 11.11.12
Version 11.11.19
Version 11.11.26
Version 11.11.5
Version 11.12.03
Version 11.9.10
Version 11.9.14
Version 11.9.17
Version 11.9.24
Running on/withPlatform Versions
Wordpress
Wordpress
All versions

References (12)

Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.