g0blin

3 exploits Active since Sep 2014
CVE-2015-10135 METASPLOIT CRITICAL ruby WORKING POC
WPshop <1.3.9.6 - RCE
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions before 1.3.9.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
CVSS 9.8
CVE-2014-6446 METASPLOIT ruby WORKING POC
Gravity Forms <1.5.11 - RCE
The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.
CVE-2014-6446 EXPLOITDB ruby WORKING POC
Gravity Forms <1.5.11 - RCE
The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.