S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Aug 20, 2024

CVE-2024-34982 Scanner

CVE-2024-34982 scanner - Arbitrary File Upload vulnerability in LyLme-Spage

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
lylme_spageby lylme
1.9.5
Updated Sep 18, 2026View on NVD →
Detail

LyLme-Spage is a simple and lightweight landing page script used by developers and small businesses to create personalized webpages quickly. It’s popular for its ease of use and flexibility in customization. The software is widely used to host links, images, and other resources that can be shared across different platforms. Given its use in a variety of environments, it’s crucial to ensure that the software remains secure and free from vulnerabilities. The arbitrary file upload vulnerability poses a significant threat to the integrity and security of the webpages created using this software.

The vulnerability allows attackers to upload arbitrary files to the server running LyLme-Spage. This can be exploited by attackers to upload malicious files, including scripts that could be executed on the server. The issue is found in the file upload functionality, specifically in the /include/file.php component. Successful exploitation can lead to remote code execution on the server, potentially allowing full control over the affected system.

The vulnerability resides in the /include/file.php endpoint of LyLme-Spage. The file upload function does not properly validate the file types or contents being uploaded. This allows attackers to upload PHP files disguised as images or other acceptable file types. Upon uploading, these files can be accessed and executed, leading to the execution of arbitrary code on the server. The vulnerable parameter is the "file" parameter in the POST request, which handles the uploaded file. The lack of sufficient validation mechanisms makes the application susceptible to this kind of attack.

If exploited, this vulnerability can lead to severe consequences, including unauthorized access to the server, data breaches, and the potential for further attacks such as defacement or spreading malware. Attackers could gain complete control over the affected server, leading to a compromise of all data and services hosted on it. The ability to execute arbitrary code remotely could also be leveraged to pivot into other parts of the network, causing widespread damage.

By using the security scanning services provided by S4E, you can proactively identify and mitigate vulnerabilities like this one in your digital assets. Our platform provides continuous monitoring, comprehensive reporting, and actionable insights to keep your infrastructure secure. Join our platform to take advantage of our extensive database of vulnerabilities, and ensure that your systems are protected against the latest threats. S4E is your trusted partner in maintaining a robust security posture.

References:

Solution Advice
  • Immediately update to a version of LyLme-Spage that addresses this vulnerability.
  • Implement stricter file type validation to ensure only legitimate files are allowed to be uploaded.
  • Monitor server logs for any suspicious activity related to file uploads.
  • Regularly audit your codebase for similar vulnerabilities.
  • Consider implementing a web application firewall (WAF) to filter malicious requests.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.