PT-2009-5975 · Unknown · Mcshoutbox

Sirgod

·

Published

2009-10-16

·

Updated

2017-09-19

·

CVE-2009-3716

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MCshoutbox version 1.1
Description The issue allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to admin.php, then accessing it via a direct request to the file in smilies/.
Recommendations For MCshoutbox version 1.1, consider restricting access to the admin.php file and the smilies/ directory to prevent exploitation until a patch is available. As a temporary workaround, avoid using the file upload feature in admin.php until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3716

Affected Products

Mcshoutbox