Unrated severityNVD Advisory· Published Oct 8, 2012· Updated Apr 29, 2026
CVE-2012-1125
CVE-2012-1125
Description
Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with a PHP extension, then accessing it via a direct request to the file in the directory specified by the folder parameter.
Affected products
2cpe:2.3:a:kishore_asokan:kish_guest_posting_plugin:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:kishore_asokan:kish_guest_posting_plugin:*:*:*:*:*:*:*:*range: <=1.1
- cpe:2.3:a:kishore_asokan:kish_guest_posting_plugin:1.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- archives.neohapsis.com/archives/bugtraq/2012-01/0145.htmlnvdExploit
- www.exploit-db.com/exploits/18412nvdExploit
- www.securityfocus.com/bid/51638nvdExploit
- secunia.com/advisories/47688nvdVendor Advisory
- plugins.svn.wordpress.org/kish-guest-posting/trunk/readme.txtnvd
- plugins.trac.wordpress.org/changeset/403694/kish-guest-posting/trunk/uploadify/scripts/uploadify.phpnvd
- www.openwall.com/lists/oss-security/2012/03/06/11nvd
- www.openwall.com/lists/oss-security/2012/03/06/3nvd
- www.openwall.com/lists/oss-security/2012/03/08/1nvd
- www.osvdb.org/78479nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/79563nvd
News mentions
0No linked articles in our index yet.