9 lines
No EOL
449 B
Text
9 lines
No EOL
449 B
Text
source: https://www.securityfocus.com/bid/47751/info
|
|
|
|
FestOS is prone to an arbitrary-file-upload vulnerability because the application fails to adequately sanitize user-supplied input.
|
|
|
|
An attacker can exploit this issue to upload arbitrary code and run it in the context of the webserver process.
|
|
|
|
FestOS 2.3c is vulnerable; other versions may also be affected.
|
|
|
|
http://www.example.com/[path]/admin/includes/tiny_mce/plugins/tinybrowser/upload.php |