JSBoard Remote Arbitrary Script Upload Vulnerability
BID:11983
Info
JSBoard Remote Arbitrary Script Upload Vulnerability
| Bugtraq ID: | 11983 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2004 12:00AM |
| Updated: | Dec 16 2004 12:00AM |
| Credit: | Discovery is credited to Jeremy Bae of STG Security. |
| Vulnerable: |
JSBoard JSBoard-win32 1.3.11 JSBoard JSBoard 2.0.8 JSBoard JSBoard 2.0.7 |
| Not Vulnerable: |
JSBoard JSBoard-win32 1.3.13 JSBoard JSBoard 2.0.9 |
Discussion
JSBoard Remote Arbitrary Script Upload Vulnerability
JSBoard is reported prone to a vulnerability that can allow a remote attacker to upload arbitrary PHP scripts to a vulnerable server. This issue results from insufficient sanitization of user-supplied input.
If successful, the attacker can execute arbitrary script code on a vulnerable server. This can lead to unauthorized access in the context of the application.
This issue was identified in versions of JSBoard 2.0.8 and prior and JSBoard-win32 1.3.11a prior.
JSBoard is reported prone to a vulnerability that can allow a remote attacker to upload arbitrary PHP scripts to a vulnerable server. This issue results from insufficient sanitization of user-supplied input.
If successful, the attacker can execute arbitrary script code on a vulnerable server. This can lead to unauthorized access in the context of the application.
This issue was identified in versions of JSBoard 2.0.8 and prior and JSBoard-win32 1.3.11a prior.
Exploit / POC
JSBoard Remote Arbitrary Script Upload Vulnerability
An exploit is not required.
The following proof of concept is available:
Script file name:
attack.php.hwp
An exploit is not required.
The following proof of concept is available:
Script file name:
attack.php.hwp
Solution / Fix
JSBoard Remote Arbitrary Script Upload Vulnerability
Solution:
The vendor has released JSBoard 2.0.9 and JSBoard-win32 1.3.13 to address this issue:
JSBoard JSBoard-win32 1.3.11
JSBoard JSBoard 2.0.7
JSBoard JSBoard 2.0.8
Solution:
The vendor has released JSBoard 2.0.9 and JSBoard-win32 1.3.13 to address this issue:
JSBoard JSBoard-win32 1.3.11
-
JSBoard jsboard-1.3.13.tar.gz
http://kldp.net/frs/download.php/1668/jsboard-1.3.13.tar.gz
JSBoard JSBoard 2.0.7
-
JSBoard jsboard-2.0.9.tar.gz
http://kldp.net/frs/download.php/1670/jsboard-2.0.9.tar.gz
JSBoard JSBoard 2.0.8
-
JSBoard jsboard-2.0.9.tar.gz
http://kldp.net/frs/download.php/1670/jsboard-2.0.9.tar.gz
References
JSBoard Remote Arbitrary Script Upload Vulnerability
References:
References: