vendor:
Elcom CMS - Community Manager
by:
Phil Taylor and Nadeem Salim from Sense of Security Labs
7,5
CVSS
HIGH
Insecure File Upload
434
CWE
Product Name: Elcom CMS - Community Manager
Affected Version From: Elcom Community Manager version 7.4.10
Affected Version To: 7.4.10
Patch Exists: YES
Related CWE: CVE - not yet assigned
CPE: elcom_cms_community_manager
Metasploit:
https://www.rapid7.com/db/vulnerabilities/debian-cve-2021-28704/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2021-28707/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2021-28708/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2021-28704/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2021-28707/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2021-28708/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: ASP.NET
2012
Elcom CMS – Community Manager Insecure File Upload Vulnerability – Security Advisory – SOS-12-008
The https://[server]/UploadStyleSheet.aspx script does not validate the file type passed in the parameter 'myfile0' on the server side allowing the uploading and execution of ASPX files. An attacker can upload an ASPX web shell and execute commands with web server user privileges.
Mitigation:
Upgrade to version 7.5 or later.