header-logo
Suggest Exploit
vendor:
Luftguitar CMS
by:
Abysssec Inc
6,5
CVSS
MEDIUM
Upload arbitrary file
434
CWE
Product Name: Luftguitar CMS
Affected Version From: Luftguitar CMS 2.0.2
Affected Version To: Luftguitar CMS 2.0.2
Patch Exists: NO
Related CWE: N/A
CPE: a:luftguitar_cms:luftguitar_cms:2.0.2
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013

Luftguitar CMS Vulnerability: Upload arbitrary file

This CMS have Upload arbitrary file valnerability with Image Gallery. you can upload your file with this path: http://Example.com/Backstage/Components/FreeTextBox/ftb.imagegallery.aspx. Uploaded files will be placing in this path: http://Example.com/Images/

Mitigation:

Ensure that the application is configured to only allow uploads of files with the appropriate MIME type and to reject all other files.
Source

Exploit-DB raw data:

'''
  __  __  ____         _    _ ____  
 |  \/  |/ __ \   /\  | |  | |  _ \ 
 | \  / | |  | | /  \ | |  | | |_) |
 | |\/| | |  | |/ /\ \| |  | |  _ < 
 | |  | | |__| / ____ \ |__| | |_) |
 |_|  |_|\____/_/    \_\____/|____/ 

http://www.exploit-db.com/moaub-13-luftguitar-cms-vulnerability-upload-arbitrary-file/
'''

Abysssec Inc Public Advisory
 
 
  Title            :  Luftguitar CMS Vulnerability: Upload arbitrary file
  Affected Version :  Luftguitar CMS 2.0.2
  Discovery        :  www.abysssec.com
  Vendor	   :  

  Demo  	   :  
  Download Links   :  http://sourceforge.net/projects/luftguitarcms/ 		      
		      

Description :
===========================================================================================      

  This CMS have Upload arbitrary file valnerability with Image Gallery.

  you can upload your file with this path:
    http://Example.com/Backstage/Components/FreeTextBox/ftb.imagegallery.aspx  


  Uploaded files will be placing in this path:

    http://Example.com/Images/ 


===========================================================================================