7.5
CVSSv2

CVE-2014-4912

Published: 22/03/2018 Updated: 18/04/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An Arbitrary File Upload issue exists in Frog CMS 0.9.5 due to lack of extension validation.

Vulnerable Product Search on Vulmon Subscribe to Product

frog cms project frog cms 0.9.5

Exploits

Exploit Title: Arbitrary File Upload in Frog CMS 095 Date : 2014-07-07 Exploit Author : Javid Hussain Vendor Homepage : wwwmadebyfrogcom # Exploit-DB Note: All authenticated users can upload files If the file # does not have execute permissions the CMS allows users to change them # No need to be authenticated to trigger uploaded file ...