Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

wPortfolio '/admin/upload_form.php' Arbitrary File Upload Vulnerability

wPortfolio is prone to a vulnerability that lets attackers upload arbitrary files because it fails to adequately secure access to administrative scripts.

An attacker can exploit this issue to upload arbitrary files and execute malicious code in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Versions up to and including wPortfolio 0.3 are vulnerable.







 

Privacy Statement
Copyright 2008, SecurityFocus