CVE-2012-1205
Relocate Upload < 0.20 - Remote Code Execution via abspath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-1205. PoCs published by Ben Schmidt.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in the Relocate Upload WordPress plugin (version 0.14). The vulnerability arises from improper sanitization of the 'abspath' parameter, allowing an attacker to include arbitrary remote files via the 'ru_folder' and 'abspath' GET parameters.
Description
PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in the Relocate Upload WordPress plugin (version 0.14). The vulnerability arises from improper sanitization of the 'abspath' parameter, allowing an attacker to include arbitrary remote files via the 'ru_folder' and 'abspath' GET parameters.