PT-2009-2545 · Kalptaru Infotech · Star Articles
Zorlu
·
Publicado
2009-08-25
·
Atualizado
2017-09-29
·
CVE-2008-7076
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Kalptaru Infotech Ltd. Star Articles version 6.0
Description
The issue allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile photo, then accessing it via a direct request to the file in authorphoto/. This is due to an unrestricted file upload vulnerability in user.modify.profile.php.
Recommendations
For Kalptaru Infotech Ltd. Star Articles version 6.0, restrict the types of files that can be uploaded as profile photos to prevent the execution of arbitrary code. As a temporary workaround, consider disabling the file upload feature in user.modify.profile.php until a proper fix is implemented.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Star Articles