The Admin panel in PwsPHP 1.2.2 does not properly verify uploaded picture files, which allows remote attackers to upload and possibly execute arbitrary files.
Link | Tags |
---|---|
http://www.osvdb.org/16236 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/20508 | vdb entry |
http://marc.info/?l=bugtraq&m=111565808024581&w=2 | mailing list |
http://secunia.com/advisories/15315 | third party advisory vendor advisory |