PT-2008-4422 · Benja · Benja Cms
Cwh
·
Published
2008-07-02
·
Updated
2018-10-11
·
CVE-2008-2988
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Benja CMS version 0.1
Description
The issue concerns an unrestricted file upload vulnerability. This allows remote attackers to upload and execute arbitrary PHP files. The attack is carried out via unspecified vectors, followed by a direct request to the file in the billeder/ directory.
Recommendations
For Benja CMS version 0.1, restrict access to the admin/upload.php file to prevent unauthorized file uploads. As a temporary workaround, consider disabling the file upload functionality in admin/upload.php until a patch is available.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Benja Cms