vendor:
Frog CMS
by:
Javid Hussain
9,3
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: Frog CMS
Affected Version From: 0.9.5
Affected Version To: 0.9.5
Patch Exists: Yes
Related CWE: N/A
CPE: a:madebyfrog:frog_cms:0.9.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2014
Arbitrary File Upload in Frog CMS 0.9.5
There is a possibility to upload arbitrary file in Frog CMS latest version 0.9.5. The vulnerability exist because of the filemanager plugin is not properly verifying the extension of uploaded files. Go to http://localhost/frog_095/admin/?/plugin/file_manager/images and upload an executable php file. Go to http://localhost/Frog/frog_095/public/images/ for verification.
Mitigation:
Upgrade to the latest version of Frog CMS