PT-2008-4029 · Flashblog · Flashblog

Ilker Kandemir

+1

·

Publicado

2008-06-06

·

Atualizado

2018-10-11

·

CVE-2008-2574

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FlashBlog version 0.31 beta
Description The issue concerns an unrestricted file upload vulnerability. This allows remote attackers to execute arbitrary code by uploading a .php file to the admin/Editor/imgupload.php endpoint, and then accessing it via a direct request to the file in tus imagenes/.
Recommendations For FlashBlog version 0.31 beta, restrict access to the admin/Editor/imgupload.php endpoint to prevent unauthorized file uploads, and remove any already uploaded malicious files from the tus imagenes/ directory.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2574

Produtos afetados

Flashblog