PHP Advanced Transfer Manager Arbitrary File Upload Vulnerability
BID:15074
Info
PHP Advanced Transfer Manager Arbitrary File Upload Vulnerability
| Bugtraq ID: | 15074 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2005 12:00AM |
| Updated: | Mar 11 2010 08:52PM |
| Credit: | Hamed Bazargani and indoushka. |
| Vulnerable: |
PHP Advanced Transfer Manager PHP Advanced Transfer Manager 1.30 PHP Advanced Transfer Manager PHP Advanced Transfer Manager 1.10 |
| Not Vulnerable: | |
Discussion
PHP Advanced Transfer Manager Arbitrary File Upload Vulnerability
PHP Advanced Transfer Manager is prone to a remote arbitrary-file-upload vulnerability.
This issue may allow remote attackers to upload arbitrary files, including malicious scripts, and possibly execute script code on the affected server.
PHP Advanced Transfer Manager is prone to a remote arbitrary-file-upload vulnerability.
This issue may allow remote attackers to upload arbitrary files, including malicious scripts, and possibly execute script code on the affected server.
Exploit / POC
PHP Advanced Transfer Manager Arbitrary File Upload Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PHP Advanced Transfer Manager Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP Advanced Transfer Manager Arbitrary File Upload Vulnerability
References:
References:
- phpATM Homepage (PHP Advanced Transfer Manager)