Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in class/UploadHomepage/.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/30365 | third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/492583/100/0/threaded | mailing list |
http://www.chroot.org/exploits/chroot_uu_005 | exploit |
http://www.securityfocus.com/bid/29372 | vdb entry exploit |
http://www.vupen.com/english/advisories/2008/1664 | vdb entry vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42651 | vdb entry |