ReserveLogic contains a flaw that is triggered when the admin/addlocationphotos.php fails to properly sanitize user supplied input. This may allow a local attacker to upload arbitrary files, which will subsequently execute code.
Classification
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
Uncoordinated Disclosure
OSVDB:
Authentication Required,
Web Related
Solution
OSVDB is not aware of a solution for this vulnerability.