PT-2005-3504 · Comsenz · Discuzx

Published

2005-08-17

·

Updated

2008-09-05

·

CVE-2005-2614

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Discuz! version 4.0 rc4
Description The issue allows remote attackers to execute arbitrary commands by uploading files with specific multiple extensions, such as ".php.rar", which are not properly restricted by the software.
Recommendations For Discuz! version 4.0 rc4, consider restricting file uploads to only allow specific, safe file types to prevent arbitrary command execution. As a temporary workaround, restrict access to file upload functionality until a proper fix is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2614

Affected Products

Discuzx