vendor:
Phpnuke
by:
4n0nym0us & b3hz4d
7.5
CVSS
HIGH
Arbitrary File Upload
CWE
Product Name: Phpnuke
Affected Version From: Phpnuke 8.3
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Phpnuke Arbitrary File Upload Vulnerability
Phpnuke is prone to an arbitrary-file-upload vulnerability because the application fails to adequately sanitize user-supplied input. An attacker can exploit this issue to upload arbitrary code and run it in the context of the webserver process.
Mitigation:
Apply the latest security patches or updates provided by the vendor. Disable file upload functionality if not required.