PT-2004-2453 · Moniwiki+1 · Moniwiki+1
Publicado
2004-12-31
·
Atualizado
2017-07-11
·
CVE-2004-1545
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
MoniWiki versions 1.0.9.2 and earlier
Description
The issue arises from the improper handling of files with multiple extensions by UploadFile.php in MoniWiki when used in conjunction with Apache mod mime. This allows remote attackers to upload files with names such as .php.hwp and execute arbitrary code.
Recommendations
For MoniWiki versions 1.0.9.2 and earlier, consider restricting or disabling the UploadFile.php functionality until a proper fix is applied to handle files with multiple extensions securely. Additionally, review and enforce strict file type validation and handling to prevent the upload and execution of malicious files.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Mod Mime
Moniwiki