WEBalbum Remote Command Execution Vulnerability
BID:17228
Info
WEBalbum Remote Command Execution Vulnerability
| Bugtraq ID: | 17228 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 25 2006 12:00AM |
| Updated: | Mar 27 2006 09:04PM |
| Credit: | Discovered by rgod <[email protected]>. |
| Vulnerable: |
WEBalbum WEBalbum 2.02pl |
| Not Vulnerable: | |
Discussion
WEBalbum Remote Command Execution Vulnerability
WEBalbum is prone to a remote command-execution vulnerability. The issue exists because the application fails to sanitize paths in cookies before using them in includes.
WEBalbum 2.02pl is vulnerable; earlier versions may also be affected.
WEBalbum is prone to a remote command-execution vulnerability. The issue exists because the application fails to sanitize paths in cookies before using them in includes.
WEBalbum 2.02pl is vulnerable; earlier versions may also be affected.
Exploit / POC
WEBalbum Remote Command Execution Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
WEBalbum Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]