WikiWebWeaver Index.PHP Arbitrary File Upload Vulnerability
BID:19537
Info
WikiWebWeaver Index.PHP Arbitrary File Upload Vulnerability
| Bugtraq ID: | 19537 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3676 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2006 12:00AM |
| Updated: | Sep 06 2006 03:33PM |
| Credit: | Crackers_Child is credited with the discovery of this vulnerability. |
| Vulnerable: |
WikiWebWeaver WikiWebWeaver 1 beta 2 |
| Not Vulnerable: |
WikiWebWeaver WikiWebWeaver 1.Beta 4 |
Discussion
WikiWebWeaver Index.PHP Arbitrary File Upload Vulnerability
WikiWebWeaver is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload malicious script code that will run in the context of the webserver process.
An attacker can exploit this issue by uploading and executing malicious PHP scripts.
WikiWebWeaver is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload malicious script code that will run in the context of the webserver process.
An attacker can exploit this issue by uploading and executing malicious PHP scripts.
Exploit / POC
WikiWebWeaver Index.PHP Arbitrary File Upload Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
WikiWebWeaver Index.PHP Arbitrary File Upload Vulnerability
Solution:
The vendor has released security patches to address this issue. Please see the references section for further information.
Solution:
The vendor has released security patches to address this issue. Please see the references section for further information.
References
WikiWebWeaver Index.PHP Arbitrary File Upload Vulnerability
References:
References:
- WikiWebWeaver Patch for 1 beta 2 (WikiWebWeaver)
- WikiWebWeaver Homepage (WikiWebWeaver)