vendor:
PHPnuke
by:
Net.Edit0r
8,8
CVSS
HIGH
Remote File Upload
434
CWE
Product Name: PHPnuke
Affected Version From: PHPnuke 8.2
Affected Version To: PHPnuke 8.2
Patch Exists: NO
Related CWE: N/A
CPE: a:phpnuke:phpnuke:8.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
PHPnuke 8.2 Remote Upload File Exploit
This exploit allows an attacker to upload malicious files to a vulnerable PHPnuke 8.2 website. The attacker can use the File Browser Connectors to upload any file type to the website. The uploaded file can then be accessed via the URL http://Target.com/images/uploads/File/File Name.
Mitigation:
Ensure that the file upload feature is properly configured and that only authorized users are allowed to upload files.