|
Sisfokol contains a flaw that is due to the profil.php, album_detail.php, artikel_post_filebox.php, buletin_post_filebox.php, and jurnal_post_filebox.php scripts not requiring authentication to upload files. This may allow a remote attacker to upload arbitrary PHP shell files to [Sisfokol]/filebox/. When the uploaded file is directly called, it may allow the attacker to gain access to potentially sensitive information or result in system access.
|