vendor:
Redaxo CMS
by:
mn@HackerWerkstatt
7.5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: Redaxo CMS
Affected Version From: 5.5.1
Affected Version To: 5.6.0
Patch Exists: YES
Related CWE: N/A
CPE: a:redaxo:redaxo_cms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: LinuxMint
2018
Redaxo CMS Mediapool Addon < 5.5.1 - Arbitrary File Upload
In the REDAXO CMS under version 5.6.0 the mediapool addon is vulnerable. Users who have an user-account, like editor, can use the mediapool to upload files. The mediapool addon under version 2.4.0 uses a blacklist for fileupload. For users it isn't possible upload files named: php, php4, php5, php6 or php7. But, if you name the files like php71 or php53 the blacklist-function ignore this and upload of shellcode-file is possible.
Mitigation:
Upgrade to mediapool 2.4.0 and Redaxo CMS 5.6.0