Make WordPress Core

Opened 8 years ago

Closed 6 years ago

#28994 closed defect (bug) (invalid)

Install plugin by upload file not check file type

Reported by: mix5003 Owned by:
Milestone: Priority: normal
Severity: normal Version: 3.9.1
Component: Plugins Keywords: dev-feedback has-patch
Focuses: administration Cc:

Description

Upload installs of plugins not check file type. If hacker bruteforce or get admin level access, they can run php script on my site.

To reproduce:

  1. Upload a php file via Plugins->Add New->Upload after upload it ask ftp login detail. please leave it and do 2.
  2. Use browser goto http://mysite/wp-content/uploads/[CURRENT YEAR]/[CURRENT MONTH]/filename.php

Attachments (1)

my-patch.diff (603 bytes) - added by mix5003 8 years ago.

Download all attachments as: .zip

Change History (9)

#1 @michalzuber
8 years ago

  • Keywords dev-feedback added

@mix5003
8 years ago

#2 @mix5003
8 years ago

  • Keywords has-patch added

#3 follow-up: @michalzuber
8 years ago

Blocked php file upload both on local and on live, too http://i.imgur.com/UlmXKED.png
ZIP upload was successfull, too.

#4 @mix5003
8 years ago

  • Keywords has-patch removed

#5 in reply to: ↑ 3 ; follow-up: @mix5003
8 years ago

Replying to michalzuber:

Blocked php file upload both on local and on live, too http://i.imgur.com/UlmXKED.png
ZIP upload was successfull, too.

sorry i test in my production server and it work. i guess some plugin in my production server allow zip file for upload

#6 in reply to: ↑ 5 @michalzuber
8 years ago

Replying to mix5003:

Replying to michalzuber:

Blocked php file upload both on local and on live, too http://i.imgur.com/UlmXKED.png
ZIP upload was successfull, too.

sorry i test in my production server and it work. i guess some plugin in my production server allow zip file for upload

It worked for me as described, it should be OK. Had no issues.

#7 @mix5003
8 years ago

  • Keywords has-patch added

#8 @DrewAPicture
6 years ago

  • Milestone Awaiting Review deleted
  • Resolution set to invalid
  • Status changed from new to closed

This seems to have been ruled invalid and never closed.

Note: See TracTickets for help on using tickets.