PT-2009-3981 · Adam Patterson Studio · Adam Patterson Studio Lounge Address Book

Jose Luis Gongora Fernandez

+1

·

Published

2009-04-29

·

Updated

2017-09-29

·

CVE-2009-1483

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Adam Patterson Studio Lounge Address Book version 2.5
Description: The issue allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the upload-file.php endpoint, and then accessing it via a direct request to the file in profiles/. This is reachable from index2.php.
Recommendations: For Adam Patterson Studio Lounge Address Book version 2.5, consider disabling the upload-file.php endpoint until a patch is available to prevent remote attackers from uploading malicious files. Restrict access to the profiles/ directory to minimize the risk of exploitation. Avoid using executable file extensions in uploads to prevent arbitrary code execution.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-1483

Affected Products

Adam Patterson Studio Lounge Address Book