vendor:
Flexphplink Pro
by:
Osirys
7.5
CVSS
HIGH
Arbitrary File Upload
264
CWE
Product Name: Flexphplink Pro
Affected Version From: Flexphplink Pro
Affected Version To: Flexphplink Pro
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Flexphplink Pro Arbitrary File Upload
This exploit allows an attacker to upload a malicious file to the server, which can be used to gain access to the server.
Mitigation:
Ensure that the application is configured to only allow the upload of files with specific extensions and that the application is configured to only allow the upload of files to specific directories.