upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute arbitrary PHP code, via a write_post action to the default URI under admin/.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2011-07-27T01:29:00
Updated: 2024-08-06T23:08:24.091Z
Reserved: 2011-07-13T00:00:00
Link: CVE-2011-2745
Vulnrichment
No data.
NVD
Status : Modified
Published: 2011-07-27T02:55:02.477
Modified: 2024-11-21T01:28:52.697
Link: CVE-2011-2745
Redhat
No data.