PT-2002-2563 · Nola · Nola

CVE-2002-1841

·

Publicado

2002-12-31

·

Atualizado

2024-01-26

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions NOLA versions 1.1.1 through 1.1.2
Description The document management module does not restrict the types of files that are uploaded, allowing remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.
Recommendations For versions 1.1.1 and 1.1.2, restrict the types of files that can be uploaded to the document management module to prevent the execution of arbitrary PHP files. As a temporary workaround, consider disabling the file upload feature in the document management module until a patch is available.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2002-1841

Produtos afetados

Nola