Description
phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file extension checks. Attackers can upload a PHP file disguised as a PNG, rename it, and execute system commands through a crafted web shell parameter.
Problem types
Unrestricted Upload of File with Dangerous Type
Product status
Credits
Halit AKAYDIN (hLtAkydn)
References
www.exploit-db.com/exploits/50610
www.exploit-db.com/exploits/50610 (ExploitDB-50610)
www.phpkf.com/ (Official Vendor Homepage)
www.phpkf.com/indirme.php (Software Download Page)