vendor:
eFront
by:
Pepelux
7.5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: eFront
Affected Version From: 3.5.2001
Affected Version To: 3.5.2001
Patch Exists: YES
Related CWE: N/A
CPE: a:efront:efront:3.5.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
eFront <= 3.5.1 / build 2710: Remote File Inclusion Vulnerability
Students and teachers can upload a shell.php as the avatar and next execute it as http://site/upload/student/avatars/shell.php or http://site/upload/professor/avatars/shell.php. In all sites tested, the upload directory is accessible by web.
Mitigation:
Ensure that the file upload feature is properly configured to only allow certain file types and extensions.