CVE-2016-9492
Summary
| CVE | CVE-2016-9492 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-13 20:29:00 UTC |
| Updated | 2019-10-09 23:20:00 UTC |
| Description | The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jqueryform | Php Formmail Generator | All | All | All | All |
| Application | Jqueryform | Php Formmail Generator | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PHP FormMail Generator Cross Site Scripting and Arbitrary File Upload Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Vulnerability Note VU#608591 - PHP FormMail Generator generates code vulnerable to multiple issues | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Thanks to Ibram Marzouk for reporting this vulnerability.
There are currently no legacy QID mappings associated with this CVE.