PT-2008-4029 · Flashblog · Flashblog
Ilker Kandemir
+1
·
Published
2008-06-06
·
Updated
2018-10-11
·
CVE-2008-2574
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FlashBlog version 0.31 beta
Description
The issue concerns an unrestricted file upload vulnerability. This allows remote attackers to execute arbitrary code by uploading a .php file to the admin/Editor/imgupload.php endpoint, and then accessing it via a direct request to the file in tus imagenes/.
Recommendations
For FlashBlog version 0.31 beta, restrict access to the admin/Editor/imgupload.php endpoint to prevent unauthorized file uploads, and remove any already uploaded malicious files from the tus imagenes/ directory.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flashblog