PT-2012-2125 · Moxiecode Systems+1 · Tinymce+1
Egidio Romano
+1
·
Publicado
2012-08-31
·
Atualizado
2013-09-12
·
CVE-2011-5147
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FreeWebshop versions 2.2.9 R2 and earlier
Description
A static code injection issue exists in the Ajax File Manager module of the tinymce plugin. This allows remote attackers to inject arbitrary PHP code into data.php via the selected document. The exploitation can be demonstrated by a call to
ajax file cut.php and then to ajax save name.php.Recommendations
For FreeWebshop versions 2.2.9 R2 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Freewebshop
Tinymce