Exponent CMS Image Upload Arbitrary Script Execution Vulnerability
BID:15391
Info
Exponent CMS Image Upload Arbitrary Script Execution Vulnerability
| Bugtraq ID: | 15391 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2005 12:00AM |
| Updated: | Nov 11 2005 12:00AM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
Exponent Exponent 0.96 .1 |
| Not Vulnerable: |
Exponent Exponent 0.96 .4 |
Discussion
Exponent CMS Image Upload Arbitrary Script Execution Vulnerability
Exponent CMS is prone to an arbitrary script execution vulnerability. This is due to a lack of proper sanitization of user-supplied input to the image upload portion of the application.
An attacker can include remote script code and execute it in the context of an affected server.
Versions 0.x are reported to be vulnerable; an upgrade to 0.94.6 is available.
Exponent CMS is prone to an arbitrary script execution vulnerability. This is due to a lack of proper sanitization of user-supplied input to the image upload portion of the application.
An attacker can include remote script code and execute it in the context of an affected server.
Versions 0.x are reported to be vulnerable; an upgrade to 0.94.6 is available.
Exploit / POC
Exponent CMS Image Upload Arbitrary Script Execution Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Exponent CMS Image Upload Arbitrary Script Execution Vulnerability
Solution:
The vendor has released version 0.94.6 to address this issue.
Exponent Exponent 0.96 .1
Solution:
The vendor has released version 0.94.6 to address this issue.
Exponent Exponent 0.96 .1
-
Exponent exponent-0.96.4.tar.gz
http://prdownloads.sourceforge.net/exponent/exponent-0.96.4.tar.gz
References
Exponent CMS Image Upload Arbitrary Script Execution Vulnerability
References:
References:
- Exponent Changelog for version 0.96.4 (Exponent)
- Exponent Home Page (Exponent)