PT-2005-3504 · Comsenz · Discuzx
Published
2005-08-17
·
Updated
2008-09-05
·
CVE-2005-2614
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Discuz! version 4.0 rc4
Description
The issue allows remote attackers to execute arbitrary commands by uploading files with specific multiple extensions, such as ".php.rar", which are not properly restricted by the software.
Recommendations
For Discuz! version 4.0 rc4, consider restricting file uploads to only allow specific, safe file types to prevent arbitrary command execution. As a temporary workaround, restrict access to file upload functionality until a proper fix is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Discuzx