vendor:
osDate
by:
Xa7m3d
7,5
CVSS
HIGH
Upload Shell Vulnerability
434
CWE
Product Name: osDate
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 9.10
2010
osDate Upload Shell Vulnerability (uploadvideos.php)
A vulnerability in osDate allows an attacker to upload a malicious shell to the server. The attacker must first create an account and confirm it. Then, they can access the uploadvideos.php page and upload a malicious shell. The shell will be stored in the uservideos folder. The attacker can then access the shell by going to the uservideos folder.
Mitigation:
Ensure that the uservideos folder is not publicly accessible and that the uploadvideos.php page is not accessible to unauthenticated users.