Vulnerabilities > CVE-2009-4818 - Unspecified vulnerability in PHPsimplicity Simplicity of Upload 1.3.2
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif. Per: http://cwe.mitre.org/data/definitions/434.html 'CWE-434: Unrestricted Upload of File with Dangerous Type'
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Simplicity oF Upload (1.3.2) Remote File Upload Vulnerability. CVE-2009-4818. Webapps exploit for php platform |
file | exploits/php/webapps/10568.txt |
id | EDB-ID:10568 |
last seen | 2016-02-01 |
modified | 2009-12-20 |
platform | php |
port | |
published | 2009-12-20 |
reporter | Master Mind |
source | https://www.exploit-db.com/download/10568/ |
title | Simplicity oF Upload 1.3.2 - Remote File Upload Vulnerability |
type | webapps |