vendor:
N/A
by:
Sid3^effects aKa HaRi
7,5
CVSS
HIGH
Upload Vulnerability
434
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Upload Vulnerability
The user can upload there evil script by changing the extension of your script to .jpg,.bmp,.gif in the list your section in the menu. Once uploaded, the user can access the script at http://server/propertyfinder/components/com_jesectionfinder/assets/images/[evil script.php.bmp.php].
Mitigation:
Ensure that all uploaded files are validated and sanitized before being stored on the server.