CMS Made Simple 'modules/FileManager/postlet/javaUpload.php' Arbitrary File Upload Vulnerability
BID:29170
Info
CMS Made Simple 'modules/FileManager/postlet/javaUpload.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 29170 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2267 |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | EgiX |
| Vulnerable: |
CMS Made Simple CMS Made Simple 1.2.4 CMS Made Simple CMS Made Simple 1.2.2 |
| Not Vulnerable: |
CMS Made Simple CMS Made Simple 1.2.5 |
Discussion
CMS Made Simple 'modules/FileManager/postlet/javaUpload.php' Arbitrary File Upload Vulnerability
CMS Made Simple is prone to a vulnerability that lets remote attackers upload and execute arbitrary script code because the application fails to properly validate the content of files being uploaded.
An attacker can leverage this issue to execute arbitrary code on an affected computer with the privileges of the webserver process.
CMS Made Simple 1.2.4 is vulnerable; other versions may also be affected.
CMS Made Simple is prone to a vulnerability that lets remote attackers upload and execute arbitrary script code because the application fails to properly validate the content of files being uploaded.
An attacker can leverage this issue to execute arbitrary code on an affected computer with the privileges of the webserver process.
CMS Made Simple 1.2.4 is vulnerable; other versions may also be affected.
Exploit / POC
CMS Made Simple 'modules/FileManager/postlet/javaUpload.php' Arbitrary File Upload Vulnerability
Attackers may exploit this issue through a browser.
The following proof of concept is available:
Attackers may exploit this issue through a browser.
The following proof of concept is available:
Solution / Fix
CMS Made Simple 'modules/FileManager/postlet/javaUpload.php' Arbitrary File Upload Vulnerability
Solution:
The vendor released CMS Made Simple 1.2.5 to address this issue. Please see the references for more information.
CMS Made Simple CMS Made Simple 1.2.2
CMS Made Simple CMS Made Simple 1.2.4
Solution:
The vendor released CMS Made Simple 1.2.5 to address this issue. Please see the references for more information.
CMS Made Simple CMS Made Simple 1.2.2
-
CMS Made Simple cmsmadesimple-1.2.5.tar.gz
http://dev.cmsmadesimple.org/frs/download.php/2059/cmsmadesimple-1.2.5 .tar.gz
CMS Made Simple CMS Made Simple 1.2.4
-
CMS Made Simple cmsmadesimple-1.2.5.tar.gz
http://dev.cmsmadesimple.org/frs/download.php/2059/cmsmadesimple-1.2.5 .tar.gz
References
CMS Made Simple 'modules/FileManager/postlet/javaUpload.php' Arbitrary File Upload Vulnerability
References:
References:
- Announcing CMS Made Simple 1.2.5 (CMS Made Simple)
- CMS Made Simple Homepage (CMS Made Simple)