Unrestricted file upload vulnerability in LoveCMS 1.4 allows remote authenticated administrators to upload arbitrary files to /modules/content/pictures/tmp/.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://securityreason.com/securityalert/2338 | third party advisory |
http://osvdb.org/33519 | vdb entry |
http://www.securityfocus.com/bid/22675 | vdb entry exploit |
http://www.securityfocus.com/archive/1/460917/100/0/threaded | mailing list |