The academic administration system of Zhengfang University is a course selection management system for students. Currently, many colleges and universities use this educational administration system. A high-risk vulnerability has recently been detected in the system. Attackers can exploit this vulnerability to easily obtain website webshell permissions. The following describes how to fix the vulnerability:
Vulnerability Type: Upload Vulnerability
Vulnerability file:/Ftb. imagegallery. aspx
This vulnerability does not have any permission restrictions on files. Visitors can directly access this file and use the file upload function to upload the webshell files that can be parsed.
Vulnerability fix: You can set the images directory script parsing permission to none. If you have the ability, you can perform permission authentication for this file to prohibit normal user access.
Vulnerability patch: please contact Zhengfang to upgrade the websiteProgram