Vulnerability Description
UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moniwiki | Moniwiki | 1.0.8 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-12/0448.htmlPatchVendor Advisory
- http://kldp.net/scm/cvsweb.php/moniwiki/plugin/UploadFile.php.diff?cvsroot=moniw
- http://marc.info/?l=bugtraq&m=110314544711884&w=2
- http://secunia.com/advisories/13478Vendor Advisory
- http://www.securityfocus.com/bid/11951Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18493
- http://archives.neohapsis.com/archives/fulldisclosure/2004-12/0448.htmlPatchVendor Advisory
- http://kldp.net/scm/cvsweb.php/moniwiki/plugin/UploadFile.php.diff?cvsroot=moniw
- http://marc.info/?l=bugtraq&m=110314544711884&w=2
- http://secunia.com/advisories/13478Vendor Advisory
- http://www.securityfocus.com/bid/11951Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18493
FAQ
What is CVE-2004-1545?
CVE-2004-1545 is a vulnerability with a CVSS score of 5.0 (MEDIUM). UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and e...
How severe is CVE-2004-1545?
CVE-2004-1545 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1545?
Check the references section above for vendor advisories and patch information. Affected products include: Moniwiki Moniwiki.