File Upload Vulnerability in FileChucker by Encodable
CVE-2019-7216
7.8HIGH
Key Information:
- Vendor
Encodable
- Status
- Vendor
- CVE Published:
- 31 January 2019
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2019-7216?
A vulnerability has been identified in FileChucker 4.99e-free-e02 that allows attackers to exploit a filter bypass in filechucker.cgi. This weakness enables a malicious user to upload any type of file by using certain encoded characters in the file extension, such as %ph%p, allowing files like file.php to be uploaded. This exposes systems to potential execution of arbitrary code, which can lead to further compromises.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
