Description
Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension and an image content type, as demonstrated by image/jpeg.
Affected products
References
- MISChttp://www.securityfocus.com/bid/24408
- MISChttp://osvdb.org/37204
- VENDOR_ADVISORYhttp://secunia.com/advisories/25614
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/34801
- EXPLOIThttps://www.exploit-db.com/exploits/4059
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2007/2143
- MISChttp://corryl.altervista.org/index.php?mod=Download/Exploit#exploit-LRCF-v3.4.rar