vendor:
Link Request Contact Form
by:
CorryL
7.5
CVSS
HIGH
Remote code injection
Not mentioned
CWE
Product Name: Link Request Contact Form
Affected Version From: 3.4
Affected Version To: 3.4
Patch Exists: NO
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: Windows, Linux, Unix
Not mentioned
Link Request Contact Form v3.4 Remote Code Injection
Link Request Contact Form v3.4 is designed to let users request to add their website link(s) banner(s) to a website. There is a bug in the software that allows a remote attacker to inject code into the server by uploading a JPG or GIF file that contains PHP code.
Mitigation:
Not mentioned