eFront <= 3.6.10 (filesystem.class.php) Unrestricted File Upload Vulnerability

Description:

eFront contains a flaw related to the libraries/filesystem.class.php script which does not properly verify or sanitize user-uploaded files. This allows a remote attacker to upload and execute arbitrary PHP code.

References:

Disclosure Date:

October 27, 2011