vendor:
FLABER
by:
EgiX
7.5
CVSS
HIGH
Remote Command Execution
Not specified
CWE
Product Name: FLABER
Affected Version From: 1.1 RC1 and below
Affected Version To: 1.1 RC1 and below
Patch Exists: NO
Related CWE: Not specified
CPE: Not specified
Platforms Tested: Not specified
Not specified
FLABER <= 1.1 RC1 Remote Command Execution Exploit
The FLABER <= 1.1 RC1 application is vulnerable to remote command execution. An attacker can overwrite an existing file with arbitrary data by using the $_POST array. This can lead to the execution of arbitrary commands on the target system.
Mitigation:
Update to a patched version of FLABER that addresses this vulnerability. Additionally, ensure that user input is properly validated and sanitized before being used in file operations.