Exploit Graffiti CMS 1.x - Arbitrary File Upload

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
9629
Проверка EDB
  1. Пройдено
Автор
ALEXANDER CONCHA
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
null
Дата публикации
2009-09-10
Код:
Graffiti CMS includes a file manager component that allows
unauthenticated users to upload files (including asp.net pages which
allow code execution). All versions are affected by this
vulnerability.

To exploit this issue, it only suffices to access to the following URL.

http://DOMAIN_TLD/GRAFFITI_CMS_INSTALL_DIR/__utility/Telligent_Editor/editor/filemanager/browser/default/browser.html?connector=../../connectors/aspx/connector.aspx

# milw0rm.com [2009-09-10]
 
Источник
www.exploit-db.com

Похожие темы