vendor:
Luftguitar CMS
by:
Abysssec Inc
6,5
CVSS
MEDIUM
Upload arbitrary file
434
CWE
Product Name: Luftguitar CMS
Affected Version From: Luftguitar CMS 2.0.2
Affected Version To: Luftguitar CMS 2.0.2
Patch Exists: NO
Related CWE: N/A
CPE: a:luftguitar_cms:luftguitar_cms:2.0.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Luftguitar CMS Vulnerability: Upload arbitrary file
This CMS have Upload arbitrary file valnerability with Image Gallery. you can upload your file with this path: http://Example.com/Backstage/Components/FreeTextBox/ftb.imagegallery.aspx. Uploaded files will be placing in this path: http://Example.com/Images/
Mitigation:
Ensure that the application is configured to only allow uploads of files with the appropriate MIME type and to reject all other files.