CVE-2015-10137
CRITICALWebsite Contact Form With File Upload <1.3.4 - RCE
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2015-10137.
PoCs published by Kai-One001, Claudio Viviani, including Metasploit module exploits/unix/webapp/wp_nmediawebsite_file_upload.
AI-analyzed exploit summary This is a functional exploit for CVE-2015-10137, targeting a file upload vulnerability in WordPress N-Media Website Contact Form with File Uploader 1.3.4. It uploads a PHP webshell and provides an interactive shell for remote command execution.
Description
The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_file()' function in versions up to, and including, 1.3.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Exploits (2)
This is a functional exploit for CVE-2015-10137, targeting a file upload vulnerability in WordPress N-Media Website Contact Form with File Uploader 1.3.4. It uploads a PHP webshell and provides an interactive shell for remote command execution.
This Metasploit module exploits an arbitrary file upload vulnerability in the WordPress N-Media Website Contact Form plugin (version 1.3.4), allowing remote code execution via a malicious PHP file upload.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H