icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons_061

GreyMatter gm-upload.cgi Arbitrary File Upload

Medium

Synopsis

The remote host is vulnerable to a Script Injection attack.

Description

The remote host is running Greymatter, a log and journal application. This version of Greymatter is vulnerable to a flaw where an attacker can upload and execute arbitrary code with the rights of the web server. Successful exploitation would lead to the attacker executing arbitrary code that would impact confidentiality, integrity and availability.

Solution

Upgrade or patch according to vendor recommendations.