header-logo
Suggest Exploit
vendor:
GHBoard
by:
Unknown
7.5
CVSS
HIGH
Arbitrary file upload and code execution
Unknown
CWE
Product Name: GHBoard
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: Unknown
Metasploit:
Other Scripts:
Platforms Tested:
Unknown

Multiple vulnerabilities in GHBoard

Attackers can upload and download arbitrary files and execute arbitrary code within the context of the webserver process by exploiting the vulnerabilities in GHBoard.

Mitigation:

Apply the latest security patches provided by the vendor. Restrict file upload functionality to trusted users only.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/26182/info
 
GHBoard is prone to multiple vulnerabilities that let attackers upload and download arbitrary files and execute arbitrary code within the context of the webserver process.
 
http://www.example.com/ghboard/component/flashupload/data/upload_filename.xxx