PT-2011-5128 · Autosec Tools · Autosec Tools V-Cms
Published
2011-12-15
·
Updated
2011-12-15
·
CVE-2011-4828
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AutoSec Tools V-CMS version 1.0
Description
The issue allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the includes/inline image upload.php script, and then accessing it via a direct request to the file in the temp/ directory.
Recommendations
For AutoSec Tools V-CMS version 1.0, consider restricting or disabling the file upload functionality in includes/inline image upload.php until a proper fix is available, and ensure that only authorized users can upload files to prevent exploitation.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autosec Tools V-Cms