Zeroboard Arbitrary File Upload Vulnerability
BID:18465
CVE-2006-3070 |Info
Zeroboard Arbitrary File Upload Vulnerability
| Bugtraq ID: | 18465 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2006 12:00AM |
| Updated: | Jun 16 2006 08:21PM |
| Credit: | Choi Min-sung is credited with the discovery of this vulnerability. |
| Vulnerable: |
Zeroboard Zeroboard 4.1 pl8 |
| Not Vulnerable: | |
Discussion
Zeroboard Arbitrary File Upload Vulnerability
Zeroboard is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload a malicious '.htaccess' file that will remove restrictions on further file-uploads and executions.
Note that to exploit this vulnerability, the Apache 'mod_mime' module must be installed and the web directory must be configured with the Apache 'AllowOverride All' or 'AllowOverride FileInfo' webserver directives.
This issue affects versions 4.1pl8 and prior.
Zeroboard is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload a malicious '.htaccess' file that will remove restrictions on further file-uploads and executions.
Note that to exploit this vulnerability, the Apache 'mod_mime' module must be installed and the web directory must be configured with the Apache 'AllowOverride All' or 'AllowOverride FileInfo' webserver directives.
This issue affects versions 4.1pl8 and prior.
Exploit / POC
Zeroboard Arbitrary File Upload Vulnerability
This issue can be exploited with a web client.
This issue can be exploited with a web client.
Solution / Fix
Zeroboard Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]