vendor:
Social Groupie
by:
Cyb3r-1sT
9.3
CVSS
HIGH
Remote File Upload
264
CWE
Product Name: Social Groupie
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Social Groupie Exploit
After registering in the site, the attacker can go to the photos section (http://www.site.me/Photos/photos.php) and create a new album (http://www.site.me/Photos/create_album.php). The attacker can then upload a malicious shell file (shell.jpg.php or shell.php) which will be located at http://www.site.me/Member_images/
Mitigation:
Ensure that all user-uploaded files are properly validated and sanitized before being stored on the server.