vendor:
b2evolution
by:
Li Fei
7,5
CVSS
HIGH
File Upload
434
CWE
Product Name: b2evolution
Affected Version From: 6.8.2
Affected Version To: 6.8.2
Patch Exists: NO
Related CWE: N/A
CPE: a:b2evolution:b2evolution:6.8.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2016
b2evolution6.8.2stable – Upload
No need admin access for upload files and we can upload any file without bypass(.php,.exe,....). An attacker can send a specially crafted HTTP request containing a malicious file to the vulnerable server. This can allow the attacker to upload malicious files to the server and execute arbitrary code.
Mitigation:
Restrict access to the upload directory and ensure that the uploaded files are validated before being stored on the server.