Description
SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands.
Problem types
Unrestricted Upload of File with Dangerous Type
Product status
Credits
Mirabbas Ağalarov
References
www.exploit-db.com/exploits/51464
www.exploit-db.com/exploits/51464 (ExploitDB-51464)
sitemagic.org/Download.html (Official Product Webpage)
www.vulncheck.com/...-execution-via-unrestricted-file-upload (VulnCheck Advisory: SitemagicCMS 4.4.3 Remote Code Execution via Unrestricted File Upload)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.