Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker...
Vulnerability Description
Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in an unspecified directory.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-3833
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71651
- http://www.securityfocus.com/bid/50632
- http://www.kb.cert.org/vuls/id/576355
- http://secunia.com/secunia_research/2011-79/
- http://www.securityfocus.com/bid/50896
- http://www.exploit-db.com/exploits/18108
- http://secunia.com/advisories/45453
- http://packetstormsecurity.org/files/106933/sit_file_upload.rb.txt
- http://www.osvdb.org/77003
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71237
More from sitracker
View All →Affected Vendor
sitracker
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.