Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to execute arbitrary code.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/417218 | vendor advisory mailing list |
http://www.securityfocus.com/bid/15503 | vdb entry |
http://secunia.com/advisories/17655 | third party advisory vendor advisory |
http://secunia.com/advisories/17505 | third party advisory |