CVE-2012-4036 Information

Description

Unrestricted file upload vulnerability in admin.php in PBBoard 2.1.4 allows remote administrators to execute arbitrary PHP code by uploading a file with an executable extension then accessing it via a direct request to the file in the addons directory. NOTE: this vulnerability can be leveraged by remote attackers using CVE-2012-1216.

Reference

http://osvdb.org/84479 http://secunia.com/advisories/50153 http://www.pbboard.com/forums/t10352.html http://www.pbboard.com/forums/t10353.html http://www.securityfocus.com/bid/54916 https://exchange.xforce.ibmcloud.com/vulnerabilities/77508 https://www.htbridge.com/advisory/HTB23101

Share on: