PT-2012-2125 · Moxiecode Systems+1 · Tinymce+1
Egidio Romano
+1
·
Published
2012-08-31
·
Updated
2013-09-12
·
CVE-2011-5147
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FreeWebshop versions 2.2.9 R2 and earlier
Description
A static code injection issue exists in the Ajax File Manager module of the tinymce plugin. This allows remote attackers to inject arbitrary PHP code into data.php via the selected document. The exploitation can be demonstrated by a call to
ajax file cut.php and then to ajax save name.php.Recommendations
For FreeWebshop versions 2.2.9 R2 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freewebshop
Tinymce