Battle Blog Administrative Interface Arbitrary File Upload Vulnerability
Description
A vulnerability has been identified in Battle Blog, which could be exploited by remote attackers to compromise a vulnerable web server. This issue is caused by missing authentication in the "admin/uploadform.asp" script, which could be exploited by remote attackers to upload malicious PHP scripts and execute arbitrary commands with the privileges of the web server.
Vulnerable Products
Vulnerable Software: Battle Blog version 1.25 and prior