PT-2007-1349 · Etomite · Etomite Cms
Rgod
·
Publicado
2007-02-27
·
Atualizado
2018-10-16
·
CVE-2006-7070
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Etomite CMS versions 0.6.1 and earlier
Description
The issue allows remote attackers to upload and execute arbitrary files. This is achieved by uploading a file with a filename that contains a .php extension followed to a valid image extension, such as .gif or .jpg, via the
nfile[] parameter. The attacker can then call the rename function to execute the uploaded file.Recommendations
For Etomite CMS versions 0.6.1 and earlier, restrict access to the
manager/media/ibrowser/scripts/rfiles.php script to prevent unauthorized file uploads. Avoid using the nfile[] parameter with filenames that contain a .php extension followed by a valid image extension. As a temporary workaround, consider disabling the file upload functionality in the affected script until a patch is available.Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Etomite Cms