6.5
CVSSv2

CVE-2011-2745

Published: 27/07/2011 Updated: 22/09/2011
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

upload_handler.php in the swfupload extension in Chyrp 2.0 and previous versions relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute arbitrary PHP code, via a write_post action to the default URI under admin/.

Vulnerable Product Search on Vulmon Subscribe to Product

chyrp chyrp

Exploits

source: wwwsecurityfocuscom/bid/48672/info Chyrp is prone to multiple cross-site scripting vulnerabilities, a local file-include vulnerability, an arbitrary file-upload vulnerability, and a directory-traversal vulnerability An attacker may leverage these issues to execute arbitrary script code on an affected computer and in the ...