{
  "modified": "2025-08-09T19:01:28Z",
  "published": "2009-11-17T18:30:00Z",
  "id": "CVE-2009-3890",
  "details": "Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename.",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://core.trac.wordpress.org/ticket/11122"
    },
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/37332"
    },
    {
      "type": "ADVISORY",
      "url": "http://wordpress.org/development/2009/11/wordpress-2-8-6-security-release/"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.openwall.com/lists/oss-security/2009/11/15/2"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.openwall.com/lists/oss-security/2009/11/15/3"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.openwall.com/lists/oss-security/2009/11/16/1"
    },
    {
      "type": "ARTICLE",
      "url": "http://www.openwall.com/lists/oss-security/2009/11/15/2"
    },
    {
      "type": "ARTICLE",
      "url": "http://www.openwall.com/lists/oss-security/2009/11/15/3"
    },
    {
      "type": "ARTICLE",
      "url": "http://www.openwall.com/lists/oss-security/2009/11/16/1"
    },
    {
      "type": "FIX",
      "url": "http://wordpress.org/development/2009/11/wordpress-2-8-6-security-release/"
    },
    {
      "type": "REPORT",
      "url": "http://core.trac.wordpress.org/ticket/11122"
    },
    {
      "type": "WEB",
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2009-11/0142.html"
    },
    {
      "type": "WEB",
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2009-11/0149.html"
    },
    {
      "type": "WEB",
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2009-11/0153.html"
    },
    {
      "type": "WEB",
      "url": "http://www.osvdb.org/59958"
    }
  ]
}
