PT-2015-5371 · Maarch · Gec/Ged+1

Adrien Thierry

·

Published

2015-02-19

·

Updated

2015-02-21

·

CVE-2015-1587

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Maarch LetterBox versions 2.8 and earlier GEC/GED versions 1.4 and earlier
Description The issue allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a request to a predictable filename in tmp/. This is due to an unrestricted file upload vulnerability in the file to index.php file.
Recommendations For Maarch LetterBox versions 2.8 and earlier, update to a version later than 2.8 to resolve the issue. For GEC/GED versions 1.4 and earlier, update to a version later than 1.4 to resolve the issue. As a temporary workaround, consider restricting access to the file to index.php file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2015-1587

Affected Products

Gec/Ged
Maarch Letterbox