BugTraq
[Suspected Spam]New vulnerabilities in CMS SiteLogic Apr 18 2010 03:05PM
MustLive (mustlive websecurity com ua) (1 replies)
Re: [Suspected Spam]New vulnerabilities in CMS SiteLogic Apr 19 2010 07:12PM
Salvatore Fresta aka Drosophila (drosophilaxxx gmail com) (1 replies)
2010/4/18 MustLive <mustlive (at) websecurity.com (dot) ua [email concealed]>:
>
> Command Execution:
>
> It's possible to upload arbitrary files (shell upload) via module â??Banner
> system� in admin panel.
>

This is not a command execution vulnerability but an arbitrary file
upload vulnerability with very very low risk (you need to know the
access to the control panel). Many web hosting provider doesn't allow
an user to execute commands using the classic functions, such as
system, shell_execute and others.

--
Salvatore Fresta aka Drosophila
http://www.salvatorefresta.net
CWNP444351

[ reply ]
Re: New vulnerabilities in CMS SiteLogic Apr 26 2010 02:16PM
MustLive (mustlive websecurity com ua)


 

Privacy Statement
Copyright 2010, SecurityFocus