PT-2009-4687 · Dmxready · Dmxready Registration Manager
Published
2009-06-27
·
Updated
2018-10-10
·
CVE-2009-2238
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
DMXReady Registration Manager version 1.1
Description
The issue allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the
assetmanager.asp script in the includes/shared scripts/wysiwyg editor/assetmanager directory, and then accessing the uploaded file directly. This is possible due to an unrestricted file upload vulnerability.Recommendations
For DMXReady Registration Manager version 1.1, restrict access to the
assetmanager.asp script to prevent unauthorized file uploads, and consider implementing validation to only allow uploading of files with specific, non-executable extensions. As a temporary workaround, consider disabling the assetmanager.asp script until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dmxready Registration Manager