PT-2005-4870 · Efiction · Efiction
Published
2005-12-11
·
Updated
2008-09-05
·
CVE-2005-4171
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
eFiction version 1.1
Description
The issue allows remote attackers to execute arbitrary PHP code by uploading a filename with a .php extension that contains a GIF header. This passes the image validity check but executes any PHP code within the file, occurring when members are allowed to upload images through the "Upload new image" command in the "Manage Images" section.
Recommendations
For eFiction version 1.1, as a temporary workaround, consider disabling the image upload functionality until a patch is available. Restrict access to the "Manage Images" section to minimize the risk of exploitation. Avoid allowing members to upload files with .php extensions to prevent arbitrary PHP code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Efiction