vendor:
deV!L`z Clanportal
by:
Tim Weber
7,5
CVSS
HIGH
Arbitrary File Upload Vulnerability
434
CWE
Product Name: deV!L`z Clanportal
Affected Version From: 1.3.6
Affected Version To: 1.3.6
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
deV!L`z Clanportal Arbitrary File Upload Vulnerability
deV!L`z Clanportal (short "DZCP") is a suite of PHP scripts that allow anybody to create a feature-rich website for her online gaming clan. The attacker can run own code on the web sever with the same privileges as DZCP itself, enabling her to do almost anything from getting the MySQL password to hosting own files and scripts or getting a shell on the server. The attacker needs a file that is both a valid JPEG or GIF file and valid PHP (or probably other) code.
Mitigation:
Ensure that the server is running the latest version of deV!L`z Clanportal and that all security patches are applied.