Vulnerabilities > CVE-2009-4818 - Unspecified vulnerability in PHPsimplicity Simplicity of Upload 1.3.2

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
phpsimplicity
exploit available

Summary

Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif. Per: http://cwe.mitre.org/data/definitions/434.html 'CWE-434: Unrestricted Upload of File with Dangerous Type'

Vulnerable Configurations

Part Description Count
Application
Phpsimplicity
1

Exploit-Db

descriptionSimplicity oF Upload (1.3.2) Remote File Upload Vulnerability. CVE-2009-4818. Webapps exploit for php platform
fileexploits/php/webapps/10568.txt
idEDB-ID:10568
last seen2016-02-01
modified2009-12-20
platformphp
port
published2009-12-20
reporterMaster Mind
sourcehttps://www.exploit-db.com/download/10568/
titleSimplicity oF Upload 1.3.2 - Remote File Upload Vulnerability
typewebapps