← voltar
CVE-2012-10044criticalCWE-434

MobileCartly 1.0 savepage.php Arbitrary File Creation

63Vexday Risk Score

Corrija em breve. Ela tem exploit funcional público.

ssvc Attendcvss 10epss 1.3%
da publicação à arma0 dias
Publicada no NVD8 de ago.
metasploit10 de ago.
probabilidade de exploração
1.3%top 32% das CVEs
exploração observada
nãonenhuma fonte reporta
3 exploit(s) público(s)
MobileCartly version 1.0 contains an arbitrary file creation vulnerability in the savepage.php script. The application fails to perform authentication or authorization checks before invoking file_put_contents() on attacker-controlled input. An unauthenticated attacker can exploit this flaw by sending crafted HTTP GET requests to savepage.php, specifying both the filename and content. This allows arbitrary file creation within the pages/ directory or any writable path on the server, allowing remote code execution.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.