Description
ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server.
Problem types
Unrestricted Upload of File with Dangerous Type
Product status
Credits
Ünsal Furkan Harani (Zemarkhos)
References
www.exploit-db.com/exploits/50890 (ExploitDB-50890)
www.impresscms.org/ (Official ImpressCMS Homepage)
github.com/ImpressCMS/impresscms (ImpressCMS GitHub Repository)
www.vulncheck.com/...ies/impresscms-unrestricted-file-upload (VulnCheck Advisory: ImpressCMS 1.4.4 - Unrestricted File Upload)