Unrestricted file upload vulnerability in index.php in Speedywiki 2.0 allows remote authenticated users to upload and execute arbitrary PHP code by setting the upload parameter to 1.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=116302805802656&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/30131 | vdb entry |
http://secunia.com/advisories/22788 | third party advisory permissions required |
http://www.vupen.com/english/advisories/2006/4421 | vdb entry not applicable |
http://s-a-p.ca/index.php?page=OurAdvisories&id=9 | url repurposed broken link |
http://securitytracker.com/id?1017201 | vdb entry third party advisory |