PT-2017-16555 · Genix · Genixcms

Publicado

2017-01-17

·

Atualizado

2019-10-03

·

CVE-2017-5520

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GeniXCMS versions 0.0.0 through 0.0.8
Description The issue concerns the media rename feature, which fails to account for alternative PHP file extensions when checking uploaded files for PHP content. This allows users to rename and execute files with the .php6, .php7, and .phtml extensions.
Recommendations For GeniXCMS versions 0.0.0 through 0.0.8, consider restricting the upload and execution of files with alternative PHP extensions, such as .php6, .php7, and .phtml, until a proper fix is implemented. As a temporary workaround, disabling the media rename feature can help minimize the risk of exploitation.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-5520

Produtos afetados

Genixcms