elcomCMS 'UploadStyleSheet.aspx' Arbitrary File Upload Vulnerability
BID:55210
Info
elcomCMS 'UploadStyleSheet.aspx' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 55210 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2012 12:00AM |
| Updated: | Aug 24 2012 12:00AM |
| Credit: | Phil Taylor and Nadeem Salim from Sense of Security Labs. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
elcomCMS 'UploadStyleSheet.aspx' Arbitrary File Upload Vulnerability
elcomCMS is prone to an arbitrary-file-upload vulnerability.
An attacker can exploit this issue to upload arbitrary code and run it in the context of the Web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
elcomCMS 7.4.10 is vulnerable; other versions are also affected.
elcomCMS is prone to an arbitrary-file-upload vulnerability.
An attacker can exploit this issue to upload arbitrary code and run it in the context of the Web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
elcomCMS 7.4.10 is vulnerable; other versions are also affected.
Exploit / POC
elcomCMS 'UploadStyleSheet.aspx' Arbitrary File Upload Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
elcomCMS 'UploadStyleSheet.aspx' Arbitrary File Upload Vulnerability
Solution:
Report indicates that this issue has been fixed. Please contact the vendor for more information.
Solution:
Report indicates that this issue has been fixed. Please contact the vendor for more information.
References
elcomCMS 'UploadStyleSheet.aspx' Arbitrary File Upload Vulnerability
References:
References:
- elcomCMS Product page (Elcom Technology)
- Elcom CMS - Community Manager Insecure File Upload Vulnerability - Security Adv (Sense of Security)
- Elcom CMS - Community Manger Insecure File Upload Vulnerability. (Sense of Security)