vendor:
PHP Easy Downloader
by:
StAkeR
7.5
CVSS
HIGH
Remote File Creation
264
CWE
Product Name: PHP Easy Downloader
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
PHP Easy Downloader <= 1.5 Remote File Creation Exploit
This exploit allows an attacker to create a malicious file on the vulnerable server. The attacker can inject arbitrary code into the file and execute it on the server. This exploit is possible due to the lack of input validation in the save.php file.
Mitigation:
Input validation should be implemented in the save.php file to prevent malicious code injection.