vendor:
FileThingie
by:
Cakes
7.5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: FileThingie
Affected Version From: 2.5.7
Affected Version To: 2.5.7
Patch Exists: NO
Related CWE: N/A
CPE: 2.5.7
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: CentOS 7
2019
FileThingie 2.5.7 – Arbitrary File Upload
Easy arbitrary file upload vulnerability allows an attacker to upload malicious .zip archives. POST .zip file with cmd shell.
Mitigation:
Ensure that the application is configured to only allow uploads of files with specific extensions and validate the file type before allowing the upload.