vendor:
eForum
by:
Unknown
7.5
CVSS
HIGH
Arbitrary File Upload
Unknown
CWE
Product Name: eForum
Affected Version From: eForum 1.1
Affected Version To: Unknown (other versions may also be affected)
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
Arbitrary File Upload Vulnerability in eForum
The eForum application fails to properly sanitize user-supplied input, allowing an attacker to upload arbitrary code and execute it within the context of the webserver process.
Mitigation:
Unknown