PT-2012-4380 · Travelon · Travelon Express

The_Storm

·

Published

2012-05-27

·

Updated

2017-08-29

·

CVE-2012-2939

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Travelon Express version 6.2.2
Description The issue allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension using specific API endpoints, such as "airline-edit.php", "hotel-image-add.php", or "hotel-add.php".
Recommendations For Travelon Express version 6.2.2, consider restricting access to the airline-edit.php, hotel-image-add.php, and hotel-add.php endpoints to prevent exploitation until a fix is available. Additionally, restrict the upload of files with executable extensions to minimize the risk of arbitrary code execution.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2012-2939

Affected Products

Travelon Express