vendor:
Asset Manager CMS and File Editor
by:
Shichemt Alen & NeT_Own3r [ Meher Assel ]
7,5
CVSS
HIGH
Shell Upload Vulnerability
434
CWE
Product Name: Asset Manager CMS and File Editor
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:asset_manager:asset_manager_cms_and_file_editor
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Asset Manager ( Shell Upload Vulnerability )
Asset Manager is vulnerable to shell upload vulnerability. An attacker can upload a malicious shell file with the extension .php or .asp to the web server. For ASP shell File name can be like this : xxx.asp;xx.jpg
Mitigation:
Restrict the file types that can be uploaded to the web server. Validate the file type before uploading it to the server.