CVE-2013-6358: Malicious File Upload
Published Jan 23, 2020
·Updated
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.
Affected Software
1 affected component
Prestashop PrestaShop=1.5.5.0
Event History
Jan 23, 2020
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-6358?
CVE-2013-6358 has a high severity rating due to its potential for remote code execution by authenticated attackers.
2
How do I fix CVE-2013-6358?
To fix CVE-2013-6358, upgrade PrestaShop to the latest version that addresses this vulnerability.
3
What kind of attack does CVE-2013-6358 allow?
CVE-2013-6358 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile.
4
Which versions of PrestaShop are affected by CVE-2013-6358?
CVE-2013-6358 specifically affects PrestaShop version 1.5.5.0.
5
What is the attack vector for CVE-2013-6358?
The attack vector for CVE-2013-6358 involves accessing a malicious profile uploaded to the module directory.