vendor:
Real Estate Classifieds Software
by:
ZoRLu
7.5
CVSS
HIGH
Remote File Upload
434
CWE
Product Name: Real Estate Classifieds Software
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
ScriptsFeed (SF) Real Estate Classifieds Software Remote File Upload
A vulnerability in ScriptsFeed (SF) Real Estate Classifieds Software allows an attacker to upload a malicious file to the server. An attacker can register to the site, login, and then edit their profile. When they upload a logo, they can right click on the logo and select properties to copy the link. The attacker can then paste the link into their browser and upload a malicious file. The malicious file can then be accessed via the URL http://localhost/script/re_images/[id]_logo_your_shell.php
Mitigation:
Ensure that user input is properly sanitized and validated before being used in file operations.