vendor:
Japanese PHP Gallery Hosting
by:
Unknown
7.5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: Japanese PHP Gallery Hosting
Affected Version From: Not provided
Affected Version To: 7-Oct
Patch Exists: NO
Related CWE: Not provided
CPE: a:japanese_php_gallery_hosting
Platforms Tested:
2007
Arbitrary File Upload Vulnerability in Japanese PHP Gallery Hosting
Japanese PHP Gallery Hosting is prone to an arbitrary-file-upload vulnerability because it fails to adequately sanitize user-supplied input. An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Mitigation:
Update to a version released after October 2007. Implement input validation and sanitization.