vendor:
VidiScript
by:
Cyb3r-1sT
7.5
CVSS
HIGH
Remote File Upload
434
CWE
Product Name: VidiScript
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
VidiScript Remote File Upload Vulnerability
This vulnerability allows an attacker to upload a malicious file to the vulnerable website. An attacker can register on the website and then upload a malicious file in the Current Avatar section. This will allow the attacker to execute arbitrary code on the vulnerable website.
Mitigation:
The website should have a proper file upload validation mechanism in place to prevent malicious files from being uploaded.