vendor:
PHP-Fusion
by:
rgod
8,8
CVSS
HIGH
Arbitrary File Upload & Local Inclusion
434
CWE
Product Name: PHP-Fusion
Affected Version From: 6.00.110
Affected Version To: 6.00.306
Patch Exists: Yes
Related CWE: N/A
CPE: a:php-fusion:php-fusion
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
PHPFusion <= v6.00.306 avatar mod_mime arbitrary file upload & local inclusion vulnerabilities
PHPFusion is a light-weight open-source content management system (CMS) written in PHP. It utilises a mySQL database to store site content and includes a simple, comprehensive adminstration system. This vulnerability allows an attacker to upload an arbitrary file and execute it on the server, as well as include local files on the server. This vulnerability affects PHPFusion v6.00.306, v6.00.207, and v6.00.110.
Mitigation:
Upgrade to the latest version of PHPFusion, or apply the patch provided by the vendor.