vendor:
Auto Classifieds Software
by:
ZoRLu
7.5
CVSS
HIGH
Remote File Upload
434
CWE
Product Name: Auto Classifieds Software
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
ScriptsFeed (SF) Auto Classifieds Software Remote File Upload
A vulnerability in ScriptsFeed (SF) Auto Classifieds Software allows an attacker to upload a malicious file to the server. An attacker can exploit this vulnerability by registering an account on the application, logging in, and then uploading a malicious file to the server. The malicious file can then be accessed via the URL http://localhost/script/cars_images/[id]_logo_your_shell.php
Mitigation:
Ensure that the application is configured to only allow the upload of files with specific extensions and that the application is configured to only allow the upload of files with specific sizes.