vendor:
SturGeoN Upload
by:
Jihad BENABRA
7.5
CVSS
HIGH
Arbitrary File-Upload Vulnerability
434
CWE
Product Name: SturGeoN Upload
Affected Version From: SturGeoN Upload v1
Affected Version To: SturGeoN Upload v1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2006
SturGeoN Upload Remote Command Execution Exploit
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Mitigation:
Filter the uploaded files and validate the file type before uploading.