vendor:
Geeklog
by:
Unknown
7,5
CVSS
HIGH
Default Insecure Configuration & Arbitrary File Hosting
264
CWE
Product Name: Geeklog
Affected Version From: 1.6.0sr1
Affected Version To: 1.6.0sr1
Patch Exists: No
Related CWE: N/A
CPE: a:geeklog:geeklog
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Geeklog <= v1.6.0sr1 - Remote Arbitrary File Upload
Configuration settings for FCKeditor shipped with Geeklog are insecure by default. They allow attackers to view and upload files and folders under its predefined image upload directory. This is not FCKeditor's fault, the Geeklog developers enabled the insecure configuration. Abuse works whether the FCKeditor is enabled or disabled in the Geeklog configuration. File uploads are restricted by directory and type.
Mitigation:
Ensure that the configuration settings for FCKeditor are secure and that the correct file types are allowed to be uploaded.