OpenBB Arbitrary Avatar File Upload Vulnerability
BID:10218
Info
OpenBB Arbitrary Avatar File Upload Vulnerability
| Bugtraq ID: | 10218 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 26 2004 12:00AM |
| Updated: | Apr 26 2004 12:00AM |
| Credit: | Discovery of this issue is credited to Manuel Lopez <[email protected]>. |
| Vulnerable: |
OpenBB OpenBB 1.0.6 OpenBB OpenBB 1.0.5 OpenBB OpenBB 1.0 .0 RC3 OpenBB OpenBB 1.0 .0 RC2 OpenBB OpenBB 1.0 .0 RC1 OpenBB OpenBB 1.0 .0 beta1 |
| Not Vulnerable: | |
Discussion
OpenBB Arbitrary Avatar File Upload Vulnerability
Reportedly OpenBB is affected by an arbitrary avatar file upload vulnerability. This issue is due to a failure of the application to restrict the file types that are uploaded.
This issue may allow a malicious user displaying their avatar file with their posts to have arbitrary, client-side script executed in an unsuspecting user's browser within the context if the affected website; facilitating HTML injection. This this may lead to cookie based authentication credential theft as well as other attacks.
Reportedly OpenBB is affected by an arbitrary avatar file upload vulnerability. This issue is due to a failure of the application to restrict the file types that are uploaded.
This issue may allow a malicious user displaying their avatar file with their posts to have arbitrary, client-side script executed in an unsuspecting user's browser within the context if the affected website; facilitating HTML injection. This this may lead to cookie based authentication credential theft as well as other attacks.
Exploit / POC
OpenBB Arbitrary Avatar File Upload Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
OpenBB Arbitrary Avatar File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
OpenBB Arbitrary Avatar File Upload Vulnerability
References:
References:
- OpenBB Homepage (OpenBB)
- Multiple Vulnerabilities In OpenBB (JeiAr
)