PHP-Fusion Advanced MP3 Player Module Arbitrary File Upload Vulnerability
Description
Sammy Forgit has discovered a vulnerability in the Advanced MP3 Player module for PHP-Fusion, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to the infusions/mp3player_panel/upload.php script improperly validating uploaded files, which can be exploited to execute arbitrary PHP code by uploading a PHP file with an appended ".mp3" file extension.
Successful exploitation requires that Apache is not configured to handle the mime-type for media files with an ".mp3" extension (Configured to handle by default).
The vulnerability is confirmed in version 2.01. Other versions may also be affected.
Vulnerable Products
Vulnerable Software: Advanced MP3 Player 2.x (module for PHP-Fusion)