PT-2008-4537 · Phpmotion · Phpmotion

Egix

·

Published

2008-07-10

·

Updated

2017-09-29

·

CVE-2008-3117

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PHPmotion versions 2.0 and earlier
Description: The issue allows remote authenticated users to execute arbitrary code by uploading a .php file with a content type of image/gif, image/jpeg, or image/pjpeg, then accessing it via a direct request to the file under pictures/.
Recommendations: For PHPmotion versions 2.0 and earlier, restrict access to the update profile.php file to prevent unauthorized file uploads, and consider validating the content type of uploaded files to prevent malicious code execution. As a temporary workaround, consider disabling the file upload functionality in update profile.php until a proper fix is available.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3117

Affected Products

Phpmotion