PT-2007-2214 · F3Site · F3Site

Kacper

·

Published

2007-02-06

·

Updated

2017-10-19

·

CVE-2007-0764

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions F3Site versions 2.1 and earlier
Description The issue allows remote authenticated administrators to upload and execute arbitrary PHP scripts. This can be achieved by using a GIF86 header in a file in the uplf parameter, which can later be accessed via a relative pathname in the dir parameter in "adm.php".
Recommendations For F3Site versions 2.1 and earlier, restrict access to the file upload functionality to prevent remote authenticated administrators from uploading arbitrary PHP scripts. As a temporary workaround, consider disabling the file upload feature in adm.php until a patch is available. Avoid using the uplf parameter in adm.php to upload files until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0764

Affected Products

F3Site