Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers to bypass authentication and upload arbitrary files via direct requests to (1) adm/photos/images.php and (2) adm/down/files.php.
Link | Tags |
---|---|
http://www.osvdb.org/28637 | vdb entry |
http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048006.html | mailing list exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27873 | vdb entry |
http://www.osvdb.org/28638 | vdb entry |
http://securityreason.com/securityalert/2322 | third party advisory |