OpenX banner-edit.php File Upload PHP Code Execution Vulnerability
Publish date: 21 de julio de 2015
Gravedad: Medio
Fecha recomendada: 21 de julio de 2015
Descripción
Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with banner / file upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an images directory.
Revelación de la información
Apply associated Trend Micro DPI Rules.
Soluciones
Trend Micro Deep Security DPI Rule Number: 1006022