vendor:
Maarch GEC
by:
Adrien Thierry
7.5
CVSS
HIGH
Arbitrary file upload
CWE
Product Name: Maarch GEC
Affected Version From: Maarch GEC <= 1.4
Affected Version To: Maarch Letterbox <= 2.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux / Windows
2014
Maarch 1.4 Arbitrary file upload
The file "file_to_index.php" is accessible without any authentication to upload a file. This exploit code is a POC for Maarch Letterbox <= 2.4 and Maarch GEC/GED <= 1.4
Mitigation:
Implement proper authentication and access controls to prevent unauthorized file uploads.