|
|
XHP CMS "FileManager" Module Access Remote File Upload Vulnerability
|
A vulnerability has been identified in XHP CMS, which may be exploited by attackers to execute arbitrary commands. This flaw is due to access validation errors in the "inc/htmlarea/plugins/FileManager/manager.php" and "inc/htmlarea/plugins/FileManager/standalonemanager.php" scripts, which could be exploited by remote attackers to upload malicious scripts and execute arbitrary commands with the privileges of the web server.
XHP CMS version 0.5 and prior
Upgrade to XHP CMS version 0.5.1 :
http://xhp.targetit.ro//index.php?page=4
http://www.vupen.com/english/advisories/2006/1052
Vulnerability reported by rgod
2006-03-23 : Initial release
2006-03-24 : Updated Solution
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|