ImageVue Multiple Vulnerabilities
BID:16594
Info
ImageVue Multiple Vulnerabilities
| Bugtraq ID: | 16594 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2006 12:00AM |
| Updated: | Jul 20 2006 06:12PM |
| Credit: | Discovery is credited to [email protected]. |
| Vulnerable: |
ImageVue ImageVue 0.16.1 |
| Not Vulnerable: |
ImageVue ImageVue 16.2 |
Discussion
ImageVue Multiple Vulnerabilities
ImageVue is prone to multiple vulnerabilities, including unauthorized uploading of files with arbitrary extensions, authentication bypass, information disclosure, and content injection.
Successful exploitation could allow attackers to upload and possibly execute malicious files, gain access to restrict areas of the site, or inject hostile content into the site.
ImageVue is prone to multiple vulnerabilities, including unauthorized uploading of files with arbitrary extensions, authentication bypass, information disclosure, and content injection.
Successful exploitation could allow attackers to upload and possibly execute malicious files, gain access to restrict areas of the site, or inject hostile content into the site.
Exploit / POC
ImageVue Multiple Vulnerabilities
The following examples were provided:
1) check folder permissions:
http://www.example.com/dir.php
An XML-document is shown containing all folders and their permissions.
2) upload a file to a folder from the XML
http://www.example.com/admin/upload.php?path=../[foldername]
Now you're ready to upload any file.
Other vulnerabilities:
1) view dir listings
http://www.example.com/readfolder.php?path=[path]&ext=[extension]
2) querystring is passed to style and body
http://www.example.com/index.php?bgcol=[input]
The following examples were provided:
1) check folder permissions:
http://www.example.com/dir.php
An XML-document is shown containing all folders and their permissions.
2) upload a file to a folder from the XML
http://www.example.com/admin/upload.php?path=../[foldername]
Now you're ready to upload any file.
Other vulnerabilities:
1) view dir listings
http://www.example.com/readfolder.php?path=[path]&ext=[extension]
2) querystring is passed to style and body
http://www.example.com/index.php?bgcol=[input]
Solution / Fix
ImageVue Multiple Vulnerabilities
Solution:
The vendor has released ImageVue version 16.2 to resolve this issue. Please contact the vendor for more information.
Solution:
The vendor has released ImageVue version 16.2 to resolve this issue. Please contact the vendor for more information.
References
ImageVue Multiple Vulnerabilities
References:
References: