vendor:
CF Image Host
by:
hyp3rlinx
7,5
CVSS
HIGH
PHP Command Injection
78
CWE
Product Name: CF Image Host
Affected Version From: 1.65
Affected Version To: 1.6.6
Patch Exists: NO
Related CWE: N/A
CPE: a:codefuture:cf_image_host
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
N/A
CF Image Host 1.65 – 1.6.6 PHP Command Injection
CF Imagehost allows users who have access to the management area the ability to write directly to the 'set.php' page under the /inc directory that stores setting values for the 'Site Title', 'Site Slogan' etc, this allows a local attacker ability to inject specially crafted PHP command payloads to execute arbitrary operating system commands on the victim host. Possibly leading to privilege escalation, RFI, backdoors etc.. and most likely full compromise of the affected system or shared environment if applicable.
Mitigation:
Restrict access to the management area and ensure that the 'set.php' page is not writable.