UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache...
Vulnerability Description
UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-1545
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/13478
- http://www.securityfocus.com/bid/11951
- http://archives.neohapsis.com/archives/fulldisclosure/2004-12/0448.html
- http://kldp.net/scm/cvsweb.php/moniwiki/plugin/UploadFile.php.diff?cvsroot=moniwiki&only_with_tag=HEAD&r1=text&tr1=1.17&r2=text&tr2=1.16&f=h
- http://marc.info/?l=bugtraq&m=110314544711884&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18493
Affected Vendor
moniwiki
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.