PT-2007-2556 · Mtcms · Mtcms

Publicado

2007-02-27

·

Atualizado

2018-10-16

·

CVE-2007-1129

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MTCMS version 3.2
Description The issue allows remote attackers to upload and execute files due to unrestricted file upload vulnerabilities. This can be achieved via an avatar upload in an add down action or an add link action.
Recommendations For MTCMS version 3.2, consider restricting or disabling the file upload functionality in the add down and add link actions until a patch is available. Additionally, restrict access to the affected areas to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1129

Produtos afetados

Mtcms