header-logo
Suggest Exploit
vendor:
CMSLogik
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: CMSLogik
Affected Version From: 1.2.0
Affected Version To: 1.2.1
Patch Exists: NO
Related CWE: N/A
CPE: a:themelogik:cmslogik:1.2.1
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Apache/2.2.22, PHP/5.3.15
2013

CMSLogik 1.2.1 (upload_file_ajax()) Shell Upload Exploit

The vulnerability is caused due to the improper verification of uploaded files in '/application/controllers/support.php' script thru the 'upload_file_ajax()' function. This can be exploited to execute arbitrary PHP code by uploading a malicious PHP script file with multiple extensions in the '/support_files' directory. Normal user [level 113] authentication required.

Mitigation:

Ensure that the application properly validates and sanitizes user-supplied input before using it in any file operations.
Source

Exploit-DB raw data: