AJ-Fork Insecure Default Permissions Vulnerability
BID:11301
Info
AJ-Fork Insecure Default Permissions Vulnerability
| Bugtraq ID: | 11301 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2004 12:00AM |
| Updated: | Oct 01 2004 12:00AM |
| Credit: | Discovery is credited to Ahmad Muammar <[email protected]>. |
| Vulnerable: |
CutePHP CuteNews 1.3.6 CutePHP CuteNews 1.3.2 CutePHP CuteNews 1.3.1 CutePHP CuteNews 1.3 CutePHP CuteNews 0.88 AJ-Fork AJ-Fork 167 |
| Not Vulnerable: | |
Discussion
AJ-Fork Insecure Default Permissions Vulnerability
AJ-Fork is reported prone to an insecure default file permissions vulnerability. This issue arises due to a configuration error and may allow an attacker to read and write to arbitrary Web accessible files.
AJ-Fork version 167 is reported prone to this vulnerability. It is likely that other versions are affected as well.
It is reported that AJ-Fork is based on CuteNews by Cutephp. Due to code similarities all versions of CuteNews are considered vulnerable to this issue as well.
AJ-Fork is reported prone to an insecure default file permissions vulnerability. This issue arises due to a configuration error and may allow an attacker to read and write to arbitrary Web accessible files.
AJ-Fork version 167 is reported prone to this vulnerability. It is likely that other versions are affected as well.
It is reported that AJ-Fork is based on CuteNews by Cutephp. Due to code similarities all versions of CuteNews are considered vulnerable to this issue as well.
Exploit / POC
AJ-Fork Insecure Default Permissions Vulnerability
There is not exploit required.
There is not exploit required.
Solution / Fix
AJ-Fork Insecure Default Permissions Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AJ-Fork Insecure Default Permissions Vulnerability
References:
References:
- CuteNews Home Page (CutePHP)
- Homepage (AJ-Fork)
- Multiple Vulnerabilities in AJ-Fork (Ahmad Muammar
)