IMG2ASCII Unauthorized File Upload Vulnerability
BID:12040
Info
IMG2ASCII Unauthorized File Upload Vulnerability
| Bugtraq ID: | 12040 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2004 12:00AM |
| Updated: | Dec 18 2004 12:00AM |
| Credit: | Phil C. is credited with discovery of this issue. |
| Vulnerable: |
IMG2ASCII IMG2ASCII 1.16 IMG2ASCII IMG2ASCII 1.15 |
| Not Vulnerable: |
IMG2ASCII IMG2ASCII 1.17 |
Discussion
IMG2ASCII Unauthorized File Upload Vulnerability
IMG2ASCII may allow remote users to upload arbitrary files. If a malicious PHP script is uploaded to the vulnerable computer, it may be possible to request the script remotely and cause its contents to be executed. This would occur in the context of the Web server hosting the application.
The vendor has not released any further information about this vulnerability except to state that it has been addressed with the release of IMG2ASCII 1.17.
IMG2ASCII may allow remote users to upload arbitrary files. If a malicious PHP script is uploaded to the vulnerable computer, it may be possible to request the script remotely and cause its contents to be executed. This would occur in the context of the Web server hosting the application.
The vendor has not released any further information about this vulnerability except to state that it has been addressed with the release of IMG2ASCII 1.17.
Exploit / POC
IMG2ASCII Unauthorized File Upload Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
IMG2ASCII Unauthorized File Upload Vulnerability
Solution:
This issue has been addressed in IMG2ASCII 1.17.
IMG2ASCII IMG2ASCII 1.15
IMG2ASCII IMG2ASCII 1.16
Solution:
This issue has been addressed in IMG2ASCII 1.17.
IMG2ASCII IMG2ASCII 1.15
-
IMG2ASCII IMG2ASCII 1.17
http://sourceforge.net/project/showfiles.php?group_id=85061&package_id =87928
IMG2ASCII IMG2ASCII 1.16
-
IMG2ASCII IMG2ASCII 1.17
http://sourceforge.net/project/showfiles.php?group_id=85061&package_id =87928
References
IMG2ASCII Unauthorized File Upload Vulnerability
References:
References:
- IMG2ASCII 1.17 Changelog (IMG2ASCII)
- IMG2ASCII Homepage (IMG2ASCII)