漏洞描述
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the form of a safe file type (e.g., a TXT file), and then using the FileEditor (in v1.5.8 and prior) or the FileManager's rename function (in v1.5.7 and prior) to rename the file to an executable extension (e.g., ASP), and finally executing the file via an HTTP GET request to /<path_to_file>.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
blog.vonahi.iohttps://blog.vonahi.io/whats-in-a-re-name/↗github.comhttps://github.com/MacdonaldRobinson/FlexDotnetCMS/releases/tag/v1.5.9↗packetstormsecurity.comhttp://packetstormsecurity.com/files/160411/FlexDotnetCMS-1.5.8-Arbitrary-ASP-File-Upload.html↗github.comhttps://github.com/rapid7/metasploit-framework/pull/14339↗