PT-2011-5128 · Autosec Tools · Autosec Tools V-Cms

Published

2011-12-15

·

Updated

2011-12-15

·

CVE-2011-4828

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AutoSec Tools V-CMS version 1.0
Description The issue allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the includes/inline image upload.php script, and then accessing it via a direct request to the file in the temp/ directory.
Recommendations For AutoSec Tools V-CMS version 1.0, consider restricting or disabling the file upload functionality in includes/inline image upload.php until a proper fix is available, and ensure that only authorized users can upload files to prevent exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4828

Affected Products

Autosec Tools V-Cms