vendor:
Burning Board Lite
by:
indoushka
7,5
CVSS
HIGH
Upload Shell
434
CWE
Product Name: Burning Board Lite
Affected Version From: 1.0.2
Affected Version To: 1.0.2
Patch Exists: YES
Related CWE: N/A
CPE: a:woltlab:burning_board_lite:1.0.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux
2008
Burning Board Lite 1.0.2 Upload Shell Vulnerability
A vulnerability in Burning Board Lite 1.0.2 allows an attacker to upload a malicious shell to the vulnerable server. The attacker can access the shell by visiting the register.php and usercp.php pages, and then finding the shell in the images/avatars/ directory.
Mitigation:
Upgrade to the latest version of Burning Board Lite, or apply the patch provided by the vendor.