PT-2012-2114 · Epractize · Epractize Labs Subscription Manager

Jan Van Niekerk

·

Published

2012-08-30

·

Updated

2017-08-29

·

CVE-2011-5136

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions EPractize Labs Subscription Manager version 1.0
Description The issue allows remote attackers to overwrite arbitrary files. This is achieved via the db parameter in the showImg.php file.
Recommendations For EPractize Labs Subscription Manager version 1.0, consider restricting access to the showImg.php file until a patch is available. As a temporary workaround, avoid using the db parameter in the affected file to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-5136

Affected Products

Epractize Labs Subscription Manager