vendor:
Counter
by:
wlhaan hacker
7,5
CVSS
HIGH
Remote File Upload
434
CWE
Product Name: Counter
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
MobPartner Counter Remote File Upload Vulnerability
A vulnerability exists in MobPartner Counter which allows an attacker to upload a malicious file to the server. The malicious file can be uploaded by editing the shell.php.pgif file and then accessing it via the upload.php page. This can allow an attacker to gain access to the server.
Mitigation:
Ensure that all file uploads are properly validated and sanitized before being accepted by the server.