CVE-2011-2933: Malicious File Upload
Published Jan 14, 2020
·Updated
An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files with .htaccess, .php4, .php5, and .phtl extensions.
Affected Software
1 affected component
WebsiteBaker WebsiteBaker<=2.8.1
Event History
Jan 14, 2020
CVE Published
via MITRE·08:23 PM
Data Sourced
via MITRE·08:23 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2011-2933?
The severity of CVE-2011-2933 is high with a severity value of 7.2.
2
How does the vulnerability CVE-2011-2933 affect WebsiteBaker?
The vulnerability affects WebsiteBaker version 2.8.1 and earlier.
3
What is the impact of the Arbitrary File Upload vulnerability in CVE-2011-2933?
The vulnerability allows attackers to upload arbitrary files to the website's filesystem, potentially leading to remote code execution.
4
How can I fix the Arbitrary File Upload vulnerability in WebsiteBaker?
To fix the vulnerability, it is recommended to upgrade to the latest version of WebsiteBaker.
5
Is there any additional information available about CVE-2011-2933?
Yes, you can find more information about CVE-2011-2933 at the following reference link: [Openwall - oss-security](https://www.openwall.com/lists/oss-security/2011/08/19/12)