vendor:
PHP-Fusion
by:
Besim ALTINOK
N/A
CVSS
N/A
Arbitrary File Upload
CWE
Product Name: PHP-Fusion
Affected Version From: v9.03.50
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Xampp
2020
PHP-Fusion 9.03.50 – ‘Edit Profile’ Arbitrary File Upload
This system does not check the file extension when user upload photo for avatar. So you can upload PHP file like: Sample PHP code: <? phpinfo(); ?>. Name of the file: Sample PHP File name: tester.php. When you want to try to upload the image to the avatar, just, try to change the file name and content.