I-Man 0.9, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by uploading a file attachment with a .php extension.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/20857 | vdb entry third party advisory |
http://sourceforge.net/project/shownotes.php?release_id=331422 | patch broken link |
http://secunia.com/advisories/15558/ | broken link third party advisory patch vendor advisory |