Popular website plugin harboured a serious 0-day for years

The flaw in the popular file uploader allows an attacker to upload files and run their own command line shell on any affected server.

Read more: Popular website plugin harboured a serious 0-day for years

Story added 22. October 2018, content source with full text you can find at link above.