PT-2005-2583 · Php · Phpatm
Publicado
2005-05-16
·
Atualizado
2018-10-19
·
CVE-2005-1604
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PHP Advanced Transfer Manager (phpATM) version 1.21
Description
The issue allows remote attackers to upload arbitrary files, potentially leading to the execution of arbitrary PHP code. This can be achieved by using filenames that contain multiple file extensions.
Recommendations
For PHP Advanced Transfer Manager (phpATM) version 1.21, consider restricting file uploads to only allow specific, trusted file extensions as a temporary workaround until a patch is available. Additionally, restrict access to the file upload functionality to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Phpatm