Secunia Advisory SA20733easy-CMS Multiple File Extensions Vulnerability
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Liz0ziM has discovered a vulnerability in easy-CMS, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to an error in the handling of file uploads where a filename has multiple file extensions. This can be exploited to upload malicious script files inside the web root (e.g. a PHP script) via the choose_file.php script. Example: [file].php.gif Successful exploitation may allow execution of script code depending on the HTTP server configuration (it requires e.g. an Apache server with the "mod_mime" module installed). The vulnerability has been confirmed in version 0.1.2. Other versions may also be affected. Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
255 views | ![]() |
| Limny Multiple Vulnerabilities | |
354 views | ![]() |
| Ubuntu update for thunderbird | |
252 views | ![]() |
| Debian update for php5 | |