Description
CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' to Extensions_userfiles and upload a shell script to the media directory to execute arbitrary code on the server.
Problem types
CWE-403: Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')
Product status
5.15
Credits
Ahmet Ümit BAYRAM
References
www.exploit-db.com/exploits/52040 (ExploitDB-52040)
www.cmsimple.org (CMSimple Homepage)
www.cmsimple.org/downloads_cmsimple50/CMSimple_5-15.zip (CMSimple Download Page)
www.vulncheck.com/...-execution-via-extensions-configuration (VulnCheck Advisory: CMSimple 5.15 Remote Command Execution via Extensions Configuration)