The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://marc.info/?l=vuln-dev&m=102511114021370&w=2 | third party advisory mailing list |
http://marc.info/?l=vuln-dev&m=102520790718208&w=2 | third party advisory mailing list |
http://online.securityfocus.com/archive/1/280340 | mailing list vdb entry third party advisory broken link |
http://www.iss.net/security_center/static/9438.php | vdb entry broken link |
http://www.securityfocus.com/bid/5116 | patch vdb entry third party advisory broken link |