vendor:
Piwik
by:
Braeden Thomas
7.5
CVSS
HIGH
Remote File Upload
434
CWE
Product Name: Piwik
Affected Version From: All Piwik versions utilising open-flash-chart
Affected Version To: All Piwik versions utilising open-flash-chart
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Various software utilising the open-flash-chart library
2009
Piwik Build <= 1357 2009-08-02 (ofc_upload_image.php) Remote File Upload
The vulnerability exists in Piwik's implementation of 'open-flash-chart', a module which resides in the './libs/open-flash-chart/php-ofc-library' directory. The vulnerable code forces Piwik to create a directory called './libs/open-flash-chart/tmp-upload-images' which in turn creates a file which is able to hold PHP code. This code however does not function correctly if global variables are unable to be overwritten.
Mitigation:
The vulnerable code should be removed from the open-flash-chart library.