Unrestricted File Upload Vulnerability in eLitius by eLitius
CVE-2009-1659

Currently unrated

Key Information:

Status
Vendor
CVE Published:
18 May 2009

What is CVE-2009-1659?

The eLitius 1.0 application suffers from an unrestricted file upload vulnerability in the admin/uploadimage.php script. This flaw allows remote attackers to bypass access controls, enabling them to upload and potentially execute arbitrary files by disguising them as valid image formats, such as image/gif. Once uploaded, attackers can make these files accessible by requesting them from the admin/banners/ path, posing significant security risks to the web application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.