MotoCMS File Disclosure and Arbitrary File Upload Vulnerabilities
BID:57055
Info
MotoCMS File Disclosure and Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 57055 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 08 2013 12:00AM |
| Updated: | Jan 08 2013 12:00AM |
| Credit: | Akastep |
| Vulnerable: |
MotoCMS MotoCMS 1.3.3 |
| Not Vulnerable: | |
Discussion
MotoCMS File Disclosure and Arbitrary File Upload Vulnerabilities
MotoCMS is prone to a file-disclosure and an arbitrary file-upload vulnerability.
An attacker can exploit these issues to upload a file and view local files in the context of the web server process, which may aid in further attacks.
MotoCMS 1.3.3 and prior versions are vulnerable.
MotoCMS is prone to a file-disclosure and an arbitrary file-upload vulnerability.
An attacker can exploit these issues to upload a file and view local files in the context of the web server process, which may aid in further attacks.
MotoCMS 1.3.3 and prior versions are vulnerable.