vendor:
CMS
by:
t0pP8uZz
7.5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: CMS
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2008
LaserNet CMS <= 1.5 Arbitrary File Upload Exploit
This exploit allows an attacker to upload arbitrary files to the LaserNet CMS version 1.5. The exploit works by sending a POST request to the upload.php file in the FCKeditor directory. If the file upload is enabled, the attacker can upload any file to the server. If the file upload is disabled, the exploit will fail.
Mitigation:
Disable file uploads in the LaserNet CMS version 1.5.