vendor:
N/A
by:
saidinh0
7,5
CVSS
HIGH
Remote Upload Vulnerability
434
CWE
Product Name: N/A
Affected Version From: 2004
Affected Version To: 2008
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux/Unix
2010
GarageSales Remote Upload Vulnerability
This vulnerability allows an attacker to upload malicious files to a vulnerable web server. The vulnerable web server is identified by a dork inurl:post.php?Category=Garage. After the malicious file is uploaded, it can be accessed via http://[site]/up_files/YouRShell.php
Mitigation:
Ensure that the web server is configured to only allow the upload of files with specific extensions and that the web server is configured to only allow the upload of files to specific directories.