vendor:
CMS Made Simple
by:
Unknown
7.5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: CMS Made Simple
Affected Version From: 1.4.2001
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2010-3315
CPE: a:cmsmadesimple:cms_made_simple:1.4.1
Platforms Tested:
2010
Download Manager Arbitrary File Upload Vulnerability
The Download Manager module for CMS Made Simple is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Mitigation:
Update to the latest version of CMS Made Simple or apply patches provided by the vendor.