PT-2011-4057 · Chyrp · Chyrp

Andrea Barisani

·

Publicado

2011-07-27

·

Atualizado

2011-09-22

·

CVE-2011-2745

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Chyrp versions 2.0 and earlier
Description The issue allows remote authenticated users to upload a .php file and execute arbitrary PHP code via a write post action to the default URI under admin/. This is possible because the upload handler.php in the swfupload extension relies on client-side JavaScript code to restrict the file extensions of uploaded files.
Recommendations For Chyrp versions 2.0 and earlier, update the swfupload extension to properly validate and restrict file extensions on the server-side, rather than relying on client-side JavaScript code. As a temporary workaround, consider disabling the upload functionality in the admin panel until a proper fix is applied. Restrict access to the upload handler.php file to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2745

Produtos afetados

Chyrp