VBulletin Arbitrary File Upload Vulnerability
BID:19334
CVE-2006-4273 |Info
VBulletin Arbitrary File Upload Vulnerability
| Bugtraq ID: | 19334 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4273 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2006 12:00AM |
| Updated: | Jul 06 2016 01:33PM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
VBulletin VBulletin 3.5.4 |
| Not Vulnerable: | |
Discussion
VBulletin Arbitrary File Upload Vulnerability
vBulletin is prone to an arbitrary file-upload vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to upload an arbitrary remote file containing malicious HTML and JavaScript code to a bulletin-board message, and then execute arbitrary HTML and script code in the browser of a victim user in the context of the affected site.
Note that this vulnerability occurs only when the malicious message is viewed using Internet Explorer. The code contained in uploaded files will execute in the context of the victim's browser application.
vBulletin is prone to an arbitrary file-upload vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to upload an arbitrary remote file containing malicious HTML and JavaScript code to a bulletin-board message, and then execute arbitrary HTML and script code in the browser of a victim user in the context of the affected site.
Note that this vulnerability occurs only when the malicious message is viewed using Internet Explorer. The code contained in uploaded files will execute in the context of the victim's browser application.
Exploit / POC
VBulletin Arbitrary File Upload Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
VBulletin Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
VBulletin Arbitrary File Upload Vulnerability
References:
References:
- vBulletin Web Site (vBulletin)
- [email protected] (vbulletin 3.5.4 IE exploit xss)