PT-2009-4687 · Dmxready · Dmxready Registration Manager

Publicado

2009-06-27

·

Atualizado

2018-10-10

·

CVE-2009-2238

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DMXReady Registration Manager version 1.1
Description The issue allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the assetmanager.asp script in the includes/shared scripts/wysiwyg editor/assetmanager directory, and then accessing the uploaded file directly. This is possible due to an unrestricted file upload vulnerability.
Recommendations For DMXReady Registration Manager version 1.1, restrict access to the assetmanager.asp script to prevent unauthorized file uploads, and consider implementing validation to only allow uploading of files with specific, non-executable extensions. As a temporary workaround, consider disabling the assetmanager.asp script until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2009-2238

Produtos afetados

Dmxready Registration Manager