header-logo
Suggest Exploit
vendor:
AtomatiCMS
by:
Abysssec Inc
6,5
CVSS
MEDIUM
Upload arbitrary file Vulnerability
434
CWE
Product Name: AtomatiCMS
Affected Version From: AtomatiCMS 10_all
Affected Version To: AtomatiCMS 10_all
Patch Exists: NO
Related CWE: N/A
CPE: atomaticcms
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020

AtomatiCMS Upload arbitrary file Vulnerability

This version of AtomatiCMS have Upload arbitrary file Vulnerability with fckEditor in this Paths: http://Example.com/FCKeditor/editor/filemanager/browser/default/connectors/test.html and http://Example.com/FCKeditor/editor/filemanager/upload/test.html. Which your files will be in this path: .../UserFiles/

Mitigation:

Ensure that the application is not vulnerable to file upload attacks by validating the file type and size before accepting the upload.
Source

Exploit-DB raw data:

'''
  __  __  ____         _    _ ____  
 |  \/  |/ __ \   /\  | |  | |  _ \ 
 | \  / | |  | | /  \ | |  | | |_) |
 | |\/| | |  | |/ /\ \| |  | |  _ < 
 | |  | | |__| / ____ \ |__| | |_) |
 |_|  |_|\____/_/    \_\____/|____/ 

'''



Abysssec Inc Public Advisory
 
 
  Title            :  AtomatiCMS Upload arbitrary file Vulnerability
  Affected Version :  AtomatiCMS 10_all
  Discovery        :  www.abysssec.com
  Vendor	   :  http://www.atomaticsoftware.com
  Download Links   :  http://sourceforge.net/projects/atomaticms/

 
Description :
===========================================================================================      
  This version of AtomatiCMS have Upload arbitrary file Vulnerability  with fckEditor
  in this Paths:
  
       http://Example.com/FCKeditor/editor/filemanager/browser/default/connectors/test.html
       http://Example.com/FCKeditor/editor/filemanager/upload/test.html
  

   Which your files will be in this path:
       .../UserFiles/



===========================================================================================