vendor:
dokeos
by:
RoMaNcYxHaCkEr
7.5
CVSS
HIGH
Bypass Upload Shell
CWE
Product Name: dokeos
Affected Version From: 1.8.2004
Affected Version To: 1.8.2004
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
dokeos-1.8.4 Bypass Upload Shell From Your Profile (Your Cpanel)
This exploit allows an attacker to bypass the upload shell functionality in dokeos-1.8.4 and upload a shell to the user's profile. By registering in the script and accessing the profile page, the attacker can upload a renamed shell file and access it through the profile page.
Mitigation:
Upgrade to a newer version of dokeos that includes a patch for this vulnerability.