vendor:
Recipes Listing Portal
by:
ZoRLu
8.8
CVSS
HIGH
Remote File Upload
264
CWE
Product Name: Recipes Listing Portal
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
ScriptsFeed (SF) Recipes Listing Portal Remote File Upload
A vulnerability exists in ScriptsFeed (SF) Recipes Listing Portal which allows an attacker to upload arbitrary files to the server. An attacker can exploit this vulnerability by registering to the website, logging in, clicking on 'Add a Recipe' and adding a recipe. After clicking on 'View your Recipes', the attacker can right click on the photo and select properties to copy the photo link. The attacker can then paste the link in the explorer and add the path of the shell to the end of the link. This will allow the attacker to upload the shell to the server and gain access to the server.
Mitigation:
The website should have proper validation checks in place to ensure that only authorized files are uploaded to the server.