CVE-2014-5460

Tribulant Tibulant Slideshow Gallery - Improper Input Validation

Title source: rule

Description

Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Claudio Viviani · pythonwebappsphp
https://www.exploit-db.com/exploits/34681
exploitdb WORKING POC
by Jesus Ramirez Pichardo · textwebappsphp
https://www.exploit-db.com/exploits/34514
nomisec WRITEUP 2 stars
by F-0x57 · poc
https://github.com/F-0x57/CVE-2014-5460
metasploit WORKING POC EXCELLENT
by Jesus Ramirez Pichardo · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/wp_slideshowgallery_upload.rb

Scores

EPSS 0.6473
EPSS Percentile 98.5%

Details

CWE
CWE-20
Status published
Products (7)
tribulant/tibulant_slideshow_gallery 1.4
tribulant/tibulant_slideshow_gallery 1.4.1
tribulant/tibulant_slideshow_gallery 1.4.2
tribulant/tibulant_slideshow_gallery 1.4.3
tribulant/tibulant_slideshow_gallery 1.4.4
tribulant/tibulant_slideshow_gallery 1.4.5
tribulant/tibulant_slideshow_gallery < 1.4.6
Published Sep 11, 2014
Tracked Since Feb 18, 2026