vendor:
by:
Mr.Benladen
N/A
CVSS
N/A
Remote Upload
CWE
Product Name:
Affected Version From: 2004
Affected Version To: 2008
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux/Unix
2010
greeting card Remote Upload Vulnerability
The exploit allows remote upload of files through a greeting card website. After registering on the website and uploading shells, the uploaded files can be accessed at http://[site]//cards/id_thumb_evil.php. An example demo URL is http://server/cards/1275663706_thumb_oujda.php.
Mitigation:
Unknown