PT-2005-3504 · Comsenz · Discuzx

Publicado

2005-08-17

·

Atualizado

2008-09-05

·

CVE-2005-2614

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Discuz! version 4.0 rc4
Description The issue allows remote attackers to execute arbitrary commands by uploading files with specific multiple extensions, such as ".php.rar", which are not properly restricted by the software.
Recommendations For Discuz! version 4.0 rc4, consider restricting file uploads to only allow specific, safe file types to prevent arbitrary command execution. As a temporary workaround, restrict access to file upload functionality until a proper fix is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2614

Produtos afetados

Discuzx