Vulnerabilities > CVE-2012-2939 - Remote vulnerability in Itechscripts Travelon Express 6.2.2

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
itechscripts
exploit available

Summary

Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) airline-edit.php, (2) hotel-image-add.php, or (3) hotel-add.php.

Vulnerable Configurations

Part Description Count
Application
Itechscripts
1

Exploit-Db

descriptionTravelon Express CMS 6.2.2 - Multiple Vulnerabilities. CVE-2012-2938,CVE-2012-2939,CVE-2012-4281. Webapps exploit for php platform
fileexploits/php/webapps/18871.txt
idEDB-ID:18871
last seen2016-02-02
modified2012-05-13
platformphp
port
published2012-05-13
reporterVulnerability-Lab
sourcehttps://www.exploit-db.com/download/18871/
titleTravelon Express CMS 6.2.2 - Multiple Vulnerabilities
typewebapps