vendor:
Sisfokol 4.0
by:
Ramdan Yantu aka cr4wl3r from Undergroundthalo Hacking Team
7,5
CVSS
HIGH
Unauthenticated File Upload
Not available
CWE
Product Name: Sisfokol 4.0
Affected Version From: 4.0
Affected Version To: 4.0
Patch Exists: NO
Related CWE: Not yet assigned
CPE: Not available
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
2012
Undergroundthalo Hacking Team – Security Advisory
The web application is vulnerable to multiple security vulnerabilities, such as Unauthenticated File Upload. All form in direktori [Sisfokol]/janissari/k/ does not require authentication to upload a file. By issuing a POST request with a webshell embedded in a JPEG image it is possible to upload [Sisfokol]/filebox/
Mitigation:
No response from the vendor