An issue was discovered in Sitemagic CMS v4.4. In the index.php?SMExt=SMFiles URI, the user can upload a .php file to execute arbitrary code, as demonstrated by 404.php. This can only occur if the administrator neglects to set FileExtensionFilter and there are untrusted user accounts. NOTE: The maintainer states that this is not a vulnerability but a feature used in conjunction with External Modules
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| http://www.iwantacve.cn/index.php/archives/116/ |
|
History
Fri, 15 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-15T15:17:04.154Z
Reserved: 2019-02-23T00:00:00.000Z
Link: CVE-2019-9042
Updated: 2024-08-04T21:38:46.304Z
Status : Modified
Published: 2019-02-23T18:29:00.347
Modified: 2024-11-21T04:50:52.670
Link: CVE-2019-9042
No data.
OpenCVE Enrichment
No data.
Weaknesses