vendor:
theportal2
by:
siurek22
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: theportal2
Affected Version From: v2.2
Affected Version To: v2.2
Patch Exists: NO
Related CWE: N/A
CPE: a:theportal2:theportal2:2.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
web apps theportal2 v2.2 (Auth bypass) file upload
An attacker can bypass authentication by uploading a malicious file to the server using the vulnerable file upload feature. The attacker can then execute arbitrary code on the server by accessing the malicious file.
Mitigation:
Ensure that the file upload feature is properly secured and that all uploaded files are scanned for malicious content.