header-logo
Suggest Exploit
vendor:
SkaDate Lite
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
Authenticated Arbitrary PHP Code Execution
78
CWE
Product Name: SkaDate Lite
Affected Version From: 2.0 (build 7651)
Affected Version To: 2.0 (build 7651)
Patch Exists: YES
Related CWE: N/A
CPE: a:skalfa_llc:skadate_lite
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: CentOS Linux 6.5 (Final), nginx/1.6.0, PHP/5.3.28, MySQL 5.5.37
2014

SkaDate Lite 2.0 Remote Code Execution Exploit

SkaDate Lite suffers from an authenticated arbitrary PHP code execution. The vulnerability is caused due to the improper verification of uploaded files in '/admin/settings/user' script thru the 'avatar' and 'bigAvatar' POST parameters. This can be exploited to execute arbitrary PHP code by uploading a malicious PHP script file with '.php5' extension (to bypass the '.htaccess' block rule) that will be stored in '/ow_userfiles/plugins/base/avatars/' directory.

Mitigation:

Ensure that uploaded files are properly verified before being stored on the server.
Source

Exploit-DB raw data: