Unrestricted file upload vulnerability in hava_upload.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading a file with a .php;.gif extension, then accessing it via a direct request to the file in tmp/files/.
References
Configurations
Information
Published : 2012-11-17 13:55
Updated : 2017-08-28 18:32
NVD link : CVE-2012-5893
Mitre link : CVE-2012-5893
JSON object : View
CWE
Products Affected
havalite
- cms