CVE-2012-1205

Alanft Relocate-upload < 0.14 - Code Injection

Title source: rule
STIX 2.1

Description

PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ben Schmidt · textwebappsphp
https://www.exploit-db.com/exploits/17869

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47976
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/79250
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/49693

Scores

EPSS 0.0165
EPSS Percentile 82.1%

Details

CWE
CWE-94
Status published
Products (3)
alanft/relocate-upload 0.10
alanft/relocate-upload 0.11
alanft/relocate-upload < 0.14
Published Feb 24, 2012
Tracked Since Feb 18, 2026