Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary files.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://bugreport.ir/index.php?/36 | exploit |
http://securityreason.com/securityalert/3842 | third party advisory |
http://www.securityfocus.com/archive/1/491129/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/28868 | vdb entry exploit |
https://www.exploit-db.com/exploits/5478 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41922 | vdb entry |