PT-2012-2125 · Moxiecode Systems+1 · Tinymce+1

Egidio Romano

+1

·

Published

2012-08-31

·

Updated

2013-09-12

·

CVE-2011-5147

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions FreeWebshop versions 2.2.9 R2 and earlier
Description A static code injection issue exists in the Ajax File Manager module of the tinymce plugin. This allows remote attackers to inject arbitrary PHP code into data.php via the selected document. The exploitation can be demonstrated by a call to ajax file cut.php and then to ajax save name.php.
Recommendations For FreeWebshop versions 2.2.9 R2 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-5147

Affected Products

Freewebshop
Tinymce