Unrestricted file upload vulnerability in config/upload.php in Moonware (aka Dale Mooney Gallery) allows remote attackers to upload and execute arbitrary PHP files in images/, possibly related to config/admin.php.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/25455 | vdb entry |
http://securityreason.com/securityalert/3079 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36288 | vdb entry |
http://secunia.com/advisories/26633 | third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/477851/100/0/threaded | mailing list |