vendor:
Fhimage
by:
Osirys
2.6
CVSS
LOW
Remote Index Change Exploit
20
CWE
Product Name: Fhimage
Affected Version From: 1.2.2001
Affected Version To: 1.2.2001
Patch Exists: Yes
Related CWE: N/A
CPE: a:flash-here:fhimage
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Fhimage 1.2.1 Remote Index Change Exploit
This exploit allows an attacker to change the content of the index.php file of Fhimage 1.2.1, a web-based image gallery. The exploit works by sending a POST request to the imgconfig/index.php?mode=write file with the string to inject as a parameter.
Mitigation:
Update to the latest version of Fhimage.