Vulnerabilities > CVE-2015-1587 - Unspecified vulnerability in Maarch Gec/Ged and Letterbox

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
maarch
exploit available
metasploit

Summary

Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a request to a predictable filename in tmp/.

Vulnerable Configurations

Part Description Count
Application
Maarch
2

Exploit-Db

descriptionMAARCH 1.4 - Arbitrary File Upload. CVE-2015-1587. Webapps exploit for php platform
fileexploits/php/webapps/35113.php
idEDB-ID:35113
last seen2016-02-04
modified2014-10-29
platformphp
port80
published2014-10-29
reporterAdrien Thierry
sourcehttps://www.exploit-db.com/download/35113/
titleMAARCH 1.4 - Arbitrary File Upload
typewebapps

Metasploit

descriptionThis module exploits a file upload vulnerability on Maarch LetterBox 2.8 due to a lack of session and file validation in the file_to_index.php script. It allows unauthenticated users to upload files of any type and subsequently execute PHP scripts in the context of the web server.
idMSF:EXPLOIT/UNIX/WEBAPP/MAARCH_LETTERBOX_FILE_UPLOAD
last seen2020-06-13
modified2018-10-01
published2015-02-12
referenceshttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1587
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/unix/webapp/maarch_letterbox_file_upload.rb
titleMaarch LetterBox Unrestricted File Upload

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/130383/maarch_letterbox_file_upload.rb.txt
idPACKETSTORM:130383
last seen2016-12-05
published2015-02-12
reporterRob Carr
sourcehttps://packetstormsecurity.com/files/130383/Maarch-LetterBox-2.8-Unrestricted-File-Upload.html
titleMaarch LetterBox 2.8 Unrestricted File Upload