Vulnerabilities > CVE-2012-6509 - Unspecified vulnerability in Netartmedia CAR Portal 3.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN netartmedia
exploit available
Summary
Unrestricted file upload vulnerability in NetArt Media Car Portal 3.0 allows remote attackers to execute arbitrary PHP code by uploading a file a double extension, as demonstrated by .php%00.jpg.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Car Portal CMS 3.0 - Multiple Vulnerabilities. CVE-2012-6508,CVE-2012-6509,CVE-2012-6510. Webapps exploit for php platform |
id | EDB-ID:18801 |
last seen | 2016-02-02 |
modified | 2012-04-30 |
published | 2012-04-30 |
reporter | Vulnerability-Lab |
source | https://www.exploit-db.com/download/18801/ |
title | Car Portal CMS 3.0 - Multiple Vulnerabilities |
References
- http://packetstormsecurity.org/files/112226/Car-Portal-CMS-3.0-CSRF-XSS-Shell-Upload.html
- http://packetstormsecurity.org/files/112226/Car-Portal-CMS-3.0-CSRF-XSS-Shell-Upload.html
- http://www.securityfocus.com/bid/53267
- http://www.securityfocus.com/bid/53267
- http://www.vulnerability-lab.com/get_content.php?id=502
- http://www.vulnerability-lab.com/get_content.php?id=502