PlanetGallery Gallery_Admin.PHP Arbitrary File Upload Vulnerability
BID:19091
CVE-2006-3676 |Info
PlanetGallery Gallery_Admin.PHP Arbitrary File Upload Vulnerability
| Bugtraq ID: | 19091 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3676 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2006 12:00AM |
| Updated: | Jul 20 2006 09:12PM |
| Credit: | RedTeam is credited with the discovery of this vulnerability. |
| Vulnerable: |
PlaNet Concept planetGallery 22.5.2006 |
| Not Vulnerable: |
PlaNet Concept planetGallery 14.7.2006 |
Discussion
PlanetGallery Gallery_Admin.PHP Arbitrary File Upload Vulnerability
planetGallery is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload malicious script code that will be executed in the context of the webserver.
An attacker can exploit this issue by uploading and executing malicious PHP scripts.
Versions 22.05.2006 and prior are vulnerable to this issue.
planetGallery is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload malicious script code that will be executed in the context of the webserver.
An attacker can exploit this issue by uploading and executing malicious PHP scripts.
Versions 22.05.2006 and prior are vulnerable to this issue.
Exploit / POC
PlanetGallery Gallery_Admin.PHP Arbitrary File Upload Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
PlanetGallery Gallery_Admin.PHP Arbitrary File Upload Vulnerability
Solution:
The vendor has released version 14.07.2006 to address this issue. Please refer to the vendor's home page for more information.
Solution:
The vendor has released version 14.07.2006 to address this issue. Please refer to the vendor's home page for more information.
References
PlanetGallery Gallery_Admin.PHP Arbitrary File Upload Vulnerability
References:
References:
- PlanetGallery Home Page (PlaNet Concept)
- Advisory: Remote command execution in planetGallery (RedTeam Pentesting)