serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://blog.ripstech.com/2016/serendipity-from-file-upload-to-code-execution/ | third party advisory |
https://demo.ripstech.com/projects/serendipity_2.0.3 | third party advisory |