Unrestricted file upload vulnerability in app/lib/mlf.pl in C-BOARD Moyuku before 1.03b3 allows remote attackers to execute arbitrary code by uploading a file with a \0 character in its name.
Link | Tags |
---|---|
http://jvndb.jvn.jp/jvndb/JVNDB-2015-000018 | third party advisory vendor advisory |
http://sourceforge.jp/projects/cb-moyuku/news/ | vendor advisory |
http://jvn.jp/en/jp/JVN73261710/index.html | third party advisory vendor advisory |