vendor:
Acidcat CMS
by:
Net.Edit0r
8,8
CVSS
HIGH
Shell Upload Vulnerability
434
CWE
Product Name: Acidcat CMS
Affected Version From: 3.3.X
Affected Version To: 3.2.x
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: ASP
2010
Acidcat CMS v 3.x (fckeditor) Shell Upload Vulnerability
A vulnerability in Acidcat CMS v 3.3 (fckeditor) allows an attacker to upload a malicious ASP shell by renaming it to .asp;.jpg. The shell can be uploaded to the server via the 'fckeditor/editor/filemanager/browser/default/browser.html?Type=File&Connector=connectors/asp/connector.asp' URL. The shell can be uploaded to the 'read_write/file/' or 'public/File/' directories.
Mitigation:
Upgrade to the latest version of Acidcat CMS v 3.3 (fckeditor) and ensure that the file upload feature is properly configured.