EzUpload Multiple Unauthorized Access Vulnerabilities
BID:19175
CVE-2006-3939 |Info
EzUpload Multiple Unauthorized Access Vulnerabilities
| Bugtraq ID: | 19175 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2006 12:00AM |
| Updated: | Jul 27 2006 11:27PM |
| Credit: | [email protected] is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
ezUpload ezUpload 2.2 |
| Not Vulnerable: | |
Discussion
EzUpload Multiple Unauthorized Access Vulnerabilities
EzUpload is prone to multiple unauthorized-access vulnerabilities because the application fails to properly secure administrative scripts with an authentication mechanism.
This allows the attacker to gain unauthorized access to the application's administrative functions.
EzUpload is prone to multiple unauthorized-access vulnerabilities because the application fails to properly secure administrative scripts with an authentication mechanism.
This allows the attacker to gain unauthorized access to the application's administrative functions.
Exploit / POC
EzUpload Multiple Unauthorized Access Vulnerabilities
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
EzUpload Multiple Unauthorized Access Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
EzUpload Multiple Unauthorized Access Vulnerabilities
References:
References: