Vulnerabilities > CVE-2007-5156

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
apache
fckeditor
sitex
exploit available

Summary

Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529. Per: http://cwe.mitre.org/data/definitions/184.html 'CWE-184: Incomplete Blacklist'

Vulnerable Configurations

Part Description Count
Application
Apache
1
Application
Fckeditor
1
Application
Sitex
1

Exploit-Db

  • descriptionLa-Nai CMS. CVE-2007-5156. Webapps exploit for php platform
    fileexploits/php/webapps/5618.txt
    idEDB-ID:5618
    last seen2016-01-31
    modified2008-05-14
    platformphp
    port
    published2008-05-14
    reporterEgiX
    sourcehttps://www.exploit-db.com/download/5618/
    titleLa-Nai CMS <= 1.2.16 - fckeditor Arbitrary File Upload Exploit
    typewebapps
  • idEDB-ID:5688