Contact Form 7 3.5.3 – Crafted File Extension Upload Remote Code Execution
-
Hi All
I am scan my sites i get following. Please any one confirm how we fix this issues.
[!] Title: Contact Form 7 3.5.3 – Crafted File Extension Upload Remote Code Execution
[!] Title: GD Star Rating 1.9.22 – gd-star-rating-stats.php s Parameter SQL Injection
[!] Title: GD Star Rating 1.9.22 – gd-star-rating-stats.php Setting Manipulation CSRF
[!] Title: GD Star Rating 1.9.18 – Export Security Bypass Security Issue
[!] Title: GD Star Rating <= 1.9.16 – Cross Site Scripting
[!] Title: GD Star Rating <= 1.9.10 – gd-star-rating/export.php de Parameter SQL Injection
[!] Title: GD Star Rating 1.9.7 – gd-star-rating/widgets/widget_top.php wpfn Parameter XSS
[!] Title: WP Photo Album Plus <= 4.1.1 – SQL Injection
[!] Title: WP Photo Album Plus <= 4.8.12 – wp-photo-album-plus.php wppa-searchstring XSS
[!] Title: WP Photo Album Plus – Full Path Disclosure
[!] Title: WP Photo Album Plus – index.php wppa-tag Parameter XSS
[!] Title: WP Photo Album Plus – “commentid” Cross-Site Scripting Vulnerability
[!] Title: WP Photo Album Plus – wp-admin/admin.php edit_id Parameter XSSThanks in advance
- The topic ‘Contact Form 7 3.5.3 – Crafted File Extension Upload Remote Code Execution’ is closed to new replies.