PT-2007-3554 · Dmcms · Dmcms

Published

2007-04-24

·

Updated

2018-10-16

·

CVE-2007-2214

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DmCMS (affected versions not specified)
Description The issue concerns an unrestricted file upload vulnerability. It allows remote attackers to upload arbitrary PHP scripts. This can be achieved by placing a script's contents in both the File2 and File3 parameters and sending a request to the "ok.php?do=act" endpoint with a specific Referer.
Recommendations As a temporary workaround, consider restricting access to the includes/upload file.php script until a patch is available. Avoid using the File2 and File3 parameters in the affected endpoint until the issue is resolved. Restrict the upload of PHP files to prevent arbitrary script execution.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2214

Affected Products

Dmcms