vendor:
cardinalCms
by:
Ma3sTr0-Dz
7,5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: cardinalCms
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: NO
Related CWE: N/A
CPE: a:ckeditor:cardinalcms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
cardinalCms 1.2 (fckeditor) Arbitrary File Upload Exploit.
This exploit allows an attacker to upload arbitrary files containing malicious PHP code to a vulnerable cardinalCms 1.2 (fckeditor) application. The vulnerable code is located in the /[path]/html/news_fckeditor/editor/filemanager/upload/php/upload.php file.
Mitigation:
Ensure that the application is configured to only allow the upload of files with the appropriate file extensions and that the application is configured to only allow the upload of files with the appropriate file size.