PT-2009-3981 · Adam Patterson Studio · Adam Patterson Studio Lounge Address Book
Jose Luis Gongora Fernandez
+1
·
Published
2009-04-29
·
Updated
2017-09-29
·
CVE-2009-1483
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Adam Patterson Studio Lounge Address Book version 2.5
Description:
The issue allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the
upload-file.php endpoint, and then accessing it via a direct request to the file in profiles/. This is reachable from index2.php.Recommendations:
For Adam Patterson Studio Lounge Address Book version 2.5, consider disabling the
upload-file.php endpoint until a patch is available to prevent remote attackers from uploading malicious files. Restrict access to the profiles/ directory to minimize the risk of exploitation. Avoid using executable file extensions in uploads to prevent arbitrary code execution.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Adam Patterson Studio Lounge Address Book