Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

phpFormGenerator Arbitrary File Upload



The remote host is vulnerable to a Script Injection attack.


The remote host is running phpFormGenerator, a PHP-based tool for generating web forms. The version of phpFormGenerator installed on the remote host allows an unauthenticated attacker to create forms supporting arbitrary file uploads. This issue can then be leveraged to upload a file with arbitrary code and execute it subject to the privileges of the web server user ID.


No solution is known at this time.