vendor:
Quicksilver Forums
by:
__GiReX__
7.5
CVSS
HIGH
Local File Inclusion / Malicious Avatar Upload
98
CWE
Product Name: Quicksilver Forums
Affected Version From: 1.4.2002
Affected Version To: 1.4.2002
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2008
Quicksilver Forums <= 1.4.2 RCE Exploit (win only)
Quicksilver Forums version 1.4.2 and prior are vulnerable to a Local File Inclusion / Malicious Avatar Upload vulnerability. This vulnerability allows an attacker to upload a malicious avatar and include it to have a Remote Command Execution. This exploit works with windows servers only and works regardless php.ini settings. The bug is located in the file global.php, lines 318-329.
Mitigation:
Upgrade to the latest version of Quicksilver Forums