WSN Forum Avatar Upload PHP Code Execution Vulnerability
BID:20586
Info
WSN Forum Avatar Upload PHP Code Execution Vulnerability
| Bugtraq ID: | 20586 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 04 2006 12:00AM |
| Updated: | Oct 18 2006 07:09PM |
| Credit: | Kacper is credited with the discovery of this vulnerability. |
| Vulnerable: |
WSN Forum WSN Forum 1.3.4 |
| Not Vulnerable: | |
Discussion
WSN Forum Avatar Upload PHP Code Execution Vulnerability
The WSN Forum application is prone to an arbitrary PHP code-execution vulnerability when uploading avatar images.
If successful, attackers can execute script code with the privileges of the webserver process.
WSN Forum 1.3.4 and prior versions are affected by this issue.
The WSN Forum application is prone to an arbitrary PHP code-execution vulnerability when uploading avatar images.
If successful, attackers can execute script code with the privileges of the webserver process.
WSN Forum 1.3.4 and prior versions are affected by this issue.
Exploit / POC
WSN Forum Avatar Upload PHP Code Execution Vulnerability
Attackers can exploit this issue via a web client.
A sample exploit has been provided:
Attackers can exploit this issue via a web client.
A sample exploit has been provided:
Solution / Fix
WSN Forum Avatar Upload PHP Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].