Arbitrary Remote File Upload exploit due to uploadview.php??
Posted: Tue Aug 02, 2011 6:29 pm
My ISP recently deactivated my account due to the following exploit in Filemanagers uploadview.php file. See the following links for more information.
http://www.securityfocus.com/bid/47637
http://www.exploit-id.com/web-applicati ... ade-simple
I realize both reference CMSMS 1.9.4.1 but I saw no reference to this being fixed in 1.9.4.2 , on the boards or any recent updates to the filemanager package.
I now have access to the site and nothing appeared to have been changed but I reinstalled from fresh 1.9.4.2 and brought over my database. I filed a bug report on June 13th and was wondering if this a legitimate exploit that I need to worry about. Thanks.
Jeff
http://www.securityfocus.com/bid/47637
http://www.exploit-id.com/web-applicati ... ade-simple
I realize both reference CMSMS 1.9.4.1 but I saw no reference to this being fixed in 1.9.4.2 , on the boards or any recent updates to the filemanager package.
I now have access to the site and nothing appeared to have been changed but I reinstalled from fresh 1.9.4.2 and brought over my database. I filed a bug report on June 13th and was wondering if this a legitimate exploit that I need to worry about. Thanks.
Jeff