vendor:
PHP File Manager
by:
milw0rm.com
7,5
CVSS
HIGH
Remote File Upload Vulnerability
434
CWE
Product Name: PHP File Manager
Affected Version From: 0.9.3
Affected Version To: 0.9.3
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
PHP File Manager 0.9.3 Remote File Upload Vulnerability
PHP File Manager 0.9.3 is prone to a remote file-upload vulnerability because the application fails to adequately sanitize user-supplied input. An attacker can exploit this issue to upload arbitrary PHP code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Mitigation:
Upgrade to the latest version of PHP File Manager 0.9.3 or later.