Skip to content

Remote command execution vulnerability in 3.3.16 #1352

Open
@PicklerBox

Description

@PicklerBox

Go to the edit-theme. PHP file, click the sava Changes button below, and grab the package.
a9
b
Use.. / to change the edited_file parameter in the request package
c
Then we access index.php
d
e

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions