Description
NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
0.4
Credits
p1ckzi
References
github.com/.../2009-exploits/0904-exploits/nanocms-multi.txt
www.exploit-db.com/exploits/50997 (ExploitDB-50997)
github.com/kalyan02/NanoCMS (NanoCMS GitHub Repository)
github.com/.../2009-exploits/0904-exploits/nanocms-multi.txt (NanoCMS Exploit Archive)
www.vulncheck.com/...remote-code-execution-rce-authenticated (VulnCheck Advisory: NanoCMS 0.4 - Remote Code Execution (RCE) (Authenticated))