vendor:
I-RATER Basic
by:
indoushka
8.8
CVSS
HIGH
Shell Upload
434
CWE
Product Name: I-RATER Basic
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux
2009
I-RATER Basic Shell Upload Vulnerability
A vulnerability in I-RATER Basic allows an attacker to upload a malicious shell to the server. The attacker can register on the website and then upload the shell using the 'poza.php' page. This vulnerability affects both Windows and Linux systems.
Mitigation:
Ensure that all user-uploaded files are properly validated and sanitized before being stored on the server.