PT-2011-4057 · Chyrp · Chyrp

Andrea Barisani

·

Published

2011-07-27

·

Updated

2011-09-22

·

CVE-2011-2745

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Chyrp versions 2.0 and earlier
Description The issue allows remote authenticated users to upload a .php file and execute arbitrary PHP code via a write post action to the default URI under admin/. This is possible because the upload handler.php in the swfupload extension relies on client-side JavaScript code to restrict the file extensions of uploaded files.
Recommendations For Chyrp versions 2.0 and earlier, update the swfupload extension to properly validate and restrict file extensions on the server-side, rather than relying on client-side JavaScript code. As a temporary workaround, consider disabling the upload functionality in the admin panel until a proper fix is applied. Restrict access to the upload handler.php file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2745

Affected Products

Chyrp