Vulnerabilities > CVE-2005-2699 - File-Upload vulnerability in PHPkit 1.6.1

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
phpkit
nessus

Summary

Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a .php file to the content/images/ directory using images.php. NOTE: if a PHPKit administrator must already have access to the end system to install or modify configuration of the product, then this issue might not cross privilege boundaries, and should not be included in CVE.

Vulnerable Configurations

Part Description Count
Application
Phpkit
1

Nessus

NASL familyCGI abuses
NASL idPHPKIT_MULTIPLE_FLAWS.NASL
descriptionThe remote host is running PHP-Kit, an open source content management system written in PHP. The remote version of this software is vulnerable to multiple remote and local code execution, SQL injection and cross-site scripting flaws.
last seen2020-06-01
modified2020-06-02
plugin id15784
published2004-11-22
reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/15784
titlePHP-Kit <= 1.6.1 RC2 Multiple Vulnerabilities