vendor:
FreeWebshop
by:
Egidio Romano aka EgiX
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: FreeWebshop
Affected Version From: <= 2.2.9 R2
Affected Version To: <= 2.2.9 R2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
FreeWebshop <= 2.2.9 R2 (ajax_save_name.php) Remote Code Execution Exploit
The vulnerable code is in the ajax_save_name.php file of FreeWebshop version 2.2.9 R2. The code allows an attacker to manipulate the $selectedDocuments array, which is then displayed at line 50. This manipulation can lead to remote code execution.
Mitigation:
Update to a patched version of the software.