Geeklog Connector.PHP Arbitrary File Upload Vulnerability
BID:18767
CVE-2006-3362 |Info
Geeklog Connector.PHP Arbitrary File Upload Vulnerability
| Bugtraq ID: | 18767 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 03 2006 12:00AM |
| Updated: | Jul 20 2006 05:22PM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
Geeklog Geeklog 1.4.0sr3 |
| Not Vulnerable: |
Geeklog Geeklog 1.4.0sr4 |
Discussion
Geeklog Connector.PHP Arbitrary File Upload Vulnerability
Geeklog CMS is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload malicious script code, which will be executed in the context of the webserver process.
An attacker may compromise the application by uploading and executing malicious PHP scripts with arbitrary filename extensions, because the application fails to sanitize multiple file extensions.
Geeklog CMS is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload malicious script code, which will be executed in the context of the webserver process.
An attacker may compromise the application by uploading and executing malicious PHP scripts with arbitrary filename extensions, because the application fails to sanitize multiple file extensions.
Exploit / POC
Geeklog Connector.PHP Arbitrary File Upload Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
Geeklog Connector.PHP Arbitrary File Upload Vulnerability
Solution:
The vendor has relased geeklog 1.4.0sr4 to resolve this issue. Please refer to the vendor's home page for more information
Solution:
The vendor has relased geeklog 1.4.0sr4 to resolve this issue. Please refer to the vendor's home page for more information