KCFinder 'browse.php' Arbitrary File Upload Vulnerability
BID:66443
Info
KCFinder 'browse.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 66443 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 24 2014 12:00AM |
| Updated: | Mar 24 2014 12:00AM |
| Credit: | Black.Hack3r |
| Vulnerable: |
KCFinder KCFinder 2.53 KCFinder KCFinder 2.52 KCFinder KCFinder 2.51 |
| Not Vulnerable: | |
Discussion
KCFinder 'browse.php' Arbitrary File Upload Vulnerability
KCFinder is prone to an arbitrary file upload vulnerability.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
KCFinder 2.51 through 2.53 are vulnerable.
KCFinder is prone to an arbitrary file upload vulnerability.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
KCFinder 2.51 through 2.53 are vulnerable.
Exploit / POC
KCFinder 'browse.php' Arbitrary File Upload Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.