PT-2009-2220 · Revou · Revou Micro Blogging Tclone Plugin
S.W.A.T
·
Published
2009-04-24
·
Updated
2017-09-29
·
CVE-2008-6751
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
ReVou Micro Blogging TClone plugin (affected versions not specified)
Description:
The issue concerns an unrestricted file upload vulnerability. This allows remote attackers to execute arbitrary code by uploading a file with an executable extension and then accessing it directly. The vulnerability is specifically in the index.php file of the TClone plugin.
Recommendations:
For the TClone plugin, consider disabling the file upload functionality in index.php until a patch is available to prevent remote attackers from executing arbitrary code. Restrict access to the settings/my photo directory to minimize the risk of exploitation. Avoid using the file upload feature in the TClone plugin until the issue is resolved.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Revou Micro Blogging Tclone Plugin