Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded filename is not enforced on the server side.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/155355/Centraleyezer-Shell-Upload.html | third party advisory vdb entry |
https://link.medium.com/Y2S4ZJbMy1 | third party advisory exploit |