Unrestricted File Upload Vulnerabilities in Travelon Express by Travelon
CVE-2012-2939

Currently unrated

Key Information:

Vendor
CVE Published:
27 May 2012

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2012-2939?

Travelon Express version 6.2.2 contains multiple vulnerabilities allowing authenticated users to exploit unrestricted file uploads. By utilizing scripts such as airline-edit.php, hotel-image-add.php, or hotel-add.php, attackers can upload files with executable extensions. This could lead to remote code execution, compromising the server and potentially other connected systems. It is important for users of Travelon Express to evaluate their installations and apply necessary mitigations against these vulnerabilities.

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.