vendor:
CameraLife
by:
Mi4night
7.5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: CameraLife
Affected Version From: 2.6.2b4
Affected Version To: 2.6.2b4
Patch Exists: NO
Related CWE: N/A
CPE: cameralife
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
CameraLife-2.6.2b4 Arbitrary File Upload Vulnerability
After registering a user can upload php files which can be accessed by changing the username in the exploit section.
Mitigation:
Restrict the file types that can be uploaded and verify the file type before allowing the upload.