Easy CMS Choose_file.PHP Arbitrary File Upload Vulnerability
BID:18496
CVE-2006-3128 |Info
Easy CMS Choose_file.PHP Arbitrary File Upload Vulnerability
| Bugtraq ID: | 18496 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3128 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2006 12:00AM |
| Updated: | Feb 11 2016 07:31AM |
| Credit: | Liz0ziM is credited with the discovery of this vulnerability. |
| Vulnerable: |
EasyCMS EasyCMS 0.1.2 |
| Not Vulnerable: | |
Discussion
Easy CMS Choose_file.PHP Arbitrary File Upload Vulnerability
Easy CMS is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload malicious script code, which will be executed in the context of the webserver process.
An attacker may compromise the application by uploading and executing malicious PHP scripts with arbitrary filename extensions, because the application fails to sanitize illegal file extensions.
Easy CMS is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload malicious script code, which will be executed in the context of the webserver process.
An attacker may compromise the application by uploading and executing malicious PHP scripts with arbitrary filename extensions, because the application fails to sanitize illegal file extensions.
Exploit / POC
Easy CMS Choose_file.PHP Arbitrary File Upload Vulnerability
This issue can be exploited with a web client.
This issue can be exploited with a web client.
Solution / Fix
Easy CMS Choose_file.PHP Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Easy CMS Choose_file.PHP Arbitrary File Upload Vulnerability
References:
References: