vendor:
Max's Image Uploader
by:
indoushka
7,5
CVSS
HIGH
Shell Upload
434
CWE
Product Name: Max's Image Uploader
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2009
Max’s Image Uploader Shell Upload Vulnerability
Max's Image Uploader is vulnerable to a shell upload vulnerability. An attacker can upload a malicious file to the server and access it via the URL http://127.0.0.1/maxImageUpload/original/evil.php. This can be used to gain access to the server and execute arbitrary code.
Mitigation:
Ensure that the application is configured to only allow the upload of files with the appropriate MIME type and that the application is configured to only allow the upload of files with the appropriate file extension.