Studio Lounge Address Book Arbitrary PHP File Upload Vulnerability
Description
A vulnerability has been identified in Studio Lounge Address Book, which could be exploited by remote attackers to compromise a vulnerable web server. This issue is caused by missing authentication in the "upload-file.php" script when handling uploaded files, which could be exploited by remote attackers to upload malicious PHP scripts and execute arbitrary commands with the privileges of the web server.
Vulnerable Products
Vulnerable Software: Studio Lounge Address Book version 2.5 and prior