vendor:
PicMe
by:
indoushka
8.8
CVSS
HIGH
Upload Shell
434
CWE
Product Name: PicMe
Affected Version From: 2.1.2000
Affected Version To: 2.1.2000
Patch Exists: YES
Related CWE: N/A
CPE: a:picme:picme:2.1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows SP2 Français V.(Pnx2 2.0) + Lunix Français v.(9.4 Ubuntu)
2009
PicMe v2.1.0 Upload Shell Vulnerability
PicMe v2.1.0 is vulnerable to an upload shell vulnerability. An attacker can exploit this vulnerability by sending a malicious file to the upload page, which will be stored in the 'uploads' directory. The attacker can then access the malicious file and execute arbitrary code on the server.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of PicMe v2.1.0.