YaPiG Upload.PHP Remote Arbitrary File Upload Vulnerability
BID:13871
Info
YaPiG Upload.PHP Remote Arbitrary File Upload Vulnerability
| Bugtraq ID: | 13871 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2005 12:00AM |
| Updated: | Jun 06 2005 12:00AM |
| Credit: | This vulnerability was discovered by an anonymous person. SecWatch reported this vulnerability. |
| Vulnerable: |
YaPiG YaPig 0.94 u YaPiG YaPig 0.93 u YaPiG YaPig 0.92 b |
| Not Vulnerable: | |
Discussion
YaPiG Upload.PHP Remote Arbitrary File Upload Vulnerability
YaPiG is prone to a remote arbitrary file upload vulnerability. The issue presents itself due to a lack of sanitization performed on image files that are uploaded.
This issue can ultimately facilitate unauthorized access in the context of the Web server.
This issue is reported to affect YaPiG versions 0.92b, 0.93u and 0.94u; earlier versions may also be vulnerable.
YaPiG is prone to a remote arbitrary file upload vulnerability. The issue presents itself due to a lack of sanitization performed on image files that are uploaded.
This issue can ultimately facilitate unauthorized access in the context of the Web server.
This issue is reported to affect YaPiG versions 0.92b, 0.93u and 0.94u; earlier versions may also be vulnerable.
Exploit / POC
YaPiG Upload.PHP Remote Arbitrary File Upload Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
YaPiG Upload.PHP Remote Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
YaPiG Upload.PHP Remote Arbitrary File Upload Vulnerability
References:
References: