Opentools Attachment Mod Multiple Remote Vulnerabilities
BID:11893
Info
Opentools Attachment Mod Multiple Remote Vulnerabilities
| Bugtraq ID: | 11893 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2004 12:00AM |
| Updated: | Dec 13 2004 12:00AM |
| Credit: | Discovery of the directory traversal vulnerability is credited to Paul Laudanski (AKA Zhen-Xjell); the discovery of the file extension access control bypass is credited to Jeremy Bae at STG Security, Inc. |
| Vulnerable: |
Opentools Attachment Mod 2.3.10 Opentools Attachment Mod 2.3.9 Opentools Attachment Mod 2.3.8 Opentools Attachment Mod 2.3.7 Opentools Attachment Mod 2.3.6 Opentools Attachment Mod 2.3.5 Opentools Attachment Mod 2.3.4 |
| Not Vulnerable: |
Opentools Attachment Mod 2.3.11 |
Discussion
Opentools Attachment Mod Multiple Remote Vulnerabilities
Opentools Attachment Mod is reported prone to multiple remote unspecified vulnerabilities. The following issues are reported:
A directory traversal vulnerability is reported to affect
Attachment Mod. It is reported that a remote attacker may exploit this vulnerability to add, or remove files that resides outside of the prescribed upload root directory.
An access control bypass vulnerability is reported to affect Attachment Mod. Reports indicate that due to insufficient handling of mod_mime on several unspecified file extensions, an attacker may bypass Attachment Mod restrictions and upload arbitrary script files.
Opentools Attachment Mod is reported prone to multiple remote unspecified vulnerabilities. The following issues are reported:
A directory traversal vulnerability is reported to affect
Attachment Mod. It is reported that a remote attacker may exploit this vulnerability to add, or remove files that resides outside of the prescribed upload root directory.
An access control bypass vulnerability is reported to affect Attachment Mod. Reports indicate that due to insufficient handling of mod_mime on several unspecified file extensions, an attacker may bypass Attachment Mod restrictions and upload arbitrary script files.
Exploit / POC
Opentools Attachment Mod Multiple Remote Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Opentools Attachment Mod Multiple Remote Vulnerabilities
Solution:
The vendor has released an update to address these issues:
Opentools Attachment Mod 2.3.10
Opentools Attachment Mod 2.3.4
Opentools Attachment Mod 2.3.5
Opentools Attachment Mod 2.3.6
Opentools Attachment Mod 2.3.7
Opentools Attachment Mod 2.3.8
Opentools Attachment Mod 2.3.9
Solution:
The vendor has released an update to address these issues:
Opentools Attachment Mod 2.3.10
-
Opentools Attachment Mod 2.3.11
http://sourceforge.net/project/showfiles.php?group_id=66311
Opentools Attachment Mod 2.3.4
-
Opentools Attachment Mod 2.3.11
http://sourceforge.net/project/showfiles.php?group_id=66311
Opentools Attachment Mod 2.3.5
-
Opentools Attachment Mod 2.3.11
http://sourceforge.net/project/showfiles.php?group_id=66311
Opentools Attachment Mod 2.3.6
-
Opentools Attachment Mod 2.3.11
http://sourceforge.net/project/showfiles.php?group_id=66311
Opentools Attachment Mod 2.3.7
-
Opentools Attachment Mod 2.3.11
http://sourceforge.net/project/showfiles.php?group_id=66311
Opentools Attachment Mod 2.3.8
-
Opentools Attachment Mod 2.3.11
http://sourceforge.net/project/showfiles.php?group_id=66311
Opentools Attachment Mod 2.3.9
-
Opentools Attachment Mod 2.3.11
http://sourceforge.net/project/showfiles.php?group_id=66311
References
Opentools Attachment Mod Multiple Remote Vulnerabilities
References:
References:
- Attachment Mod Version 2.3.11 released (Opentools)
- Opentools Homepage (Opentools)
- phpBB Attachment Mod Directory Traversal HTTP POST Injection (Paul Laudanski
) - STG Security Advisory: [SSA-20041215-18] Attachment Mod Vulnerability (
)