PT-2007-3554 · Dmcms · Dmcms
Published
2007-04-24
·
Updated
2018-10-16
·
CVE-2007-2214
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
DmCMS (affected versions not specified)
Description
The issue concerns an unrestricted file upload vulnerability. It allows remote attackers to upload arbitrary PHP scripts. This can be achieved by placing a script's contents in both the
File2 and File3 parameters and sending a request to the "ok.php?do=act" endpoint with a specific Referer.Recommendations
As a temporary workaround, consider restricting access to the includes/upload file.php script until a patch is available.
Avoid using the
File2 and File3 parameters in the affected endpoint until the issue is resolved.
Restrict the upload of PHP files to prevent arbitrary script execution.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dmcms