vendor:
FOSS Gallery Admin Version
by:
Pepelux
9.3
CVSS
HIGH
Remote Arbitrary Upload Vulnerability
434
CWE
Product Name: FOSS Gallery Admin Version
Affected Version From: <= 1.0
Affected Version To: <= 1.0
Patch Exists: YES
Related CWE: N/A
CPE: a:foss_gallery_admin_version:foss_gallery_admin_version
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Mac, Windows
2008
FOSS Gallery Admin Version <= 1.0 / Remote Arbitrary Upload Vulnerability
FOSS Gallery Admin Version <= 1.0 is vulnerable to a remote arbitrary upload vulnerability. The vulnerability exists due to insufficient validation of user-supplied input in the 'processFiles.php' script. An attacker can exploit this vulnerability to upload arbitrary files to the vulnerable server, which can lead to remote code execution. The attacker can directly POST in the 3rd step (processFiles.php) with the uploadNeed set to 1 and the uploadFile0 set to the file to be uploaded.
Mitigation:
Upgrade to the latest version of FOSS Gallery Admin Version.