PT-2018-15260 · Zzzphp · Zzzphp Cms
Publicado
2018-12-13
·
Atualizado
2020-07-14
·
CVE-2018-20127
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
zzzphp cms version 1.5.8
Description
An issue was discovered that allows remote attackers to delete arbitrary files. This is possible due to the
del file function in the /admin/save.php endpoint, which can be exploited by using a mixed-case extension and an extra '.' character. For example, while "php" is blocked, a path like "F:/1.phP" can succeed.Recommendations
For zzzphp cms version 1.5.8, consider restricting access to the
del file function in the /admin/save.php endpoint until a patch is available. As a temporary workaround, avoid using mixed-case extensions in file paths to minimize the risk of exploitation.Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zzzphp Cms