vendor:
Agora-Project
by:
Misa3l
7,5
CVSS
HIGH
Remote Shell Upload
434
CWE
Product Name: Agora-Project
Affected Version From: 2.12.11_12-2011
Affected Version To: 2.12.11_12-2011
Patch Exists: NO
Related CWE: N/A
CPE: a:agora-project:agora-project:2.12.11_12-2011
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Debian 6.0
2012
agora-project_2.12.11_12-2011 Remote Shell Upload
Agora-Project is an intuitive groupware under GPL (Based on PHP/MySQL). It contains many modules: File Manager (with versioning), Calendars (with resource calendars), Task Manager, Bookmark manager, Contacts, News, Forum, Instant Messaging, etc. An attacker can exploit this vulnerability by uploading a malicious file to the vulnerable server using a specially crafted form. The malicious file can then be accessed via the server's web interface.
Mitigation:
Ensure that the web server is configured to only allow the upload of trusted files and that all uploaded files are scanned for malicious content.