Unrestricted File Upload Vulnerabilities in Travelon Express by Travelon
CVE-2012-2939
Currently unrated
What is CVE-2012-2939?
Travelon Express version 6.2.2 contains multiple vulnerabilities allowing authenticated users to exploit unrestricted file uploads. By utilizing scripts such as airline-edit.php, hotel-image-add.php, or hotel-add.php, attackers can upload files with executable extensions. This could lead to remote code execution, compromising the server and potentially other connected systems. It is important for users of Travelon Express to evaluate their installations and apply necessary mitigations against these vulnerabilities.