Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [Full-disclosure] CMS Made Simple: SQL injection

  Disable website access for sites running Webspeed

  Post Nuke v4bJournal Module Sql Inject

  Bradford CampusManager v3.1(6) Sensitive Data Disclosure

From:John McGuire <bugtraq_(at)_greeneandassoc.com>
Date:03.05.2007
Subject:12All File Upload Vulnerability

Author: John McGuire
Company: ActiveCampaign
Product: 1-2-All
Version: 4.5x - 4.53.13
Flaw: Arbitrary File Upload
Vendor Notified: Yes
Patch Available: Yes
Patch Location:
http://www.activecampaign.com/support/forum/showthread.php?t=3293


URL:
http:
//{12All_Location}/admin/functions/editor/editor/filemanager/browser/default/brow
ser.html

Description: The FCKeditor module used to create HTML emails appears to
check filenames against a blacklist of bad extensions. Extensions such
as php4 and php5 are not in this list, and can be executed and run
depending on server configuration.

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server