vendor:
CMF
by:
Egidio Romano aka EgiX
7,5
CVSS
HIGH
Unrestricted File Upload
434
CWE
Product Name: CMF
Affected Version From: 0.1.5
Affected Version To: 0.1.5
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
appRain CMF <= 0.1.5 (uploadify.php) Unrestricted File Upload Exploit
Restricted access to this script isn't properly realized, so an attacker might be able to upload a malicious file with a double extension (ex: .php.jpg) and execute arbitrary code.
Mitigation:
Restrict access to the uploadify.php script and ensure that only valid file types are allowed to be uploaded.