EyeOS Aplic.PHP Arbitrary File Upload Vulnerability
BID:21639
Info
EyeOS Aplic.PHP Arbitrary File Upload Vulnerability
| Bugtraq ID: | 21639 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2006 12:00AM |
| Updated: | Dec 18 2006 08:28PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
eyeOS eyeOS 0.9.3 -2a eyeOS eyeOS 0.9.1 eyeOS eyeOS 0.9 eyeOS eyeOS 0.8.10 eyeOS eyeOS 0.8.9 eyeOS eyeOS 0.8.5 eyeOS eyeOS 0.8.4 -r1 eyeOS eyeOS 0.8.4 eyeOS eyeOS 0.8.3 -r2 eyeOS eyeOS 0.8.3 |
| Not Vulnerable: |
eyeOS eyeOS 0.9.3 -4 eyeOS eyeOS 0.9.3 -3 |
Discussion
EyeOS Aplic.PHP Arbitrary File Upload Vulnerability
EyeOS is prone to an arbitrary file-upload vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue could allow an attacker to upload and execute arbitrary script code in the context of the affected webserver process. This may help the attacker compromise the application; other attacks are possible.
Versions prior to 0.9.3-3 are vulnerable.
EyeOS is prone to an arbitrary file-upload vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue could allow an attacker to upload and execute arbitrary script code in the context of the affected webserver process. This may help the attacker compromise the application; other attacks are possible.
Versions prior to 0.9.3-3 are vulnerable.
Exploit / POC
EyeOS Aplic.PHP Arbitrary File Upload Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
EyeOS Aplic.PHP Arbitrary File Upload Vulnerability
Solution:
The vendor has released version 0.9.3-3 to address this issue. Please see the references for more information.
eyeOS eyeOS 0.8.10
eyeOS eyeOS 0.8.3
eyeOS eyeOS 0.8.3 -r2
eyeOS eyeOS 0.8.4 -r1
eyeOS eyeOS 0.8.4
eyeOS eyeOS 0.8.5
eyeOS eyeOS 0.8.9
eyeOS eyeOS 0.9
eyeOS eyeOS 0.9.1
eyeOS eyeOS 0.9.3 -2a
Solution:
The vendor has released version 0.9.3-3 to address this issue. Please see the references for more information.
eyeOS eyeOS 0.8.10
-
eyeOS eyeOS-0.9.3-3.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-3.tar.gz?modtime=11 65836720&big_mirror=0 -
eyeOS eyeOS-0.9.3-4.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-4.tar.gz?modtime=11 65836720&big_mirror=0
eyeOS eyeOS 0.8.3
-
eyeOS eyeOS-0.9.3-3.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-3.tar.gz?modtime=11 65836720&big_mirror=0 -
eyeOS eyeOS-0.9.3-4.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-4.tar.gz?modtime=11 65836720&big_mirror=0
eyeOS eyeOS 0.8.3 -r2
-
eyeOS eyeOS-0.9.3-3.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-3.tar.gz?modtime=11 65836720&big_mirror=0 -
eyeOS eyeOS-0.9.3-4.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-4.tar.gz?modtime=11 65836720&big_mirror=0
eyeOS eyeOS 0.8.4 -r1
-
eyeOS eyeOS-0.9.3-3.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-3.tar.gz?modtime=11 65836720&big_mirror=0 -
eyeOS eyeOS-0.9.3-4.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-4.tar.gz?modtime=11 65836720&big_mirror=0
eyeOS eyeOS 0.8.4
-
eyeOS eyeOS-0.9.3-3.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-3.tar.gz?modtime=11 65836720&big_mirror=0 -
eyeOS eyeOS-0.9.3-4.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-4.tar.gz?modtime=11 65836720&big_mirror=0
eyeOS eyeOS 0.8.5
-
eyeOS eyeOS-0.9.3-3.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-3.tar.gz?modtime=11 65836720&big_mirror=0 -
eyeOS eyeOS-0.9.3-4.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-4.tar.gz?modtime=11 65836720&big_mirror=0
eyeOS eyeOS 0.8.9
-
eyeOS eyeOS-0.9.3-3.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-3.tar.gz?modtime=11 65836720&big_mirror=0 -
eyeOS eyeOS-0.9.3-4.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-4.tar.gz?modtime=11 65836720&big_mirror=0
eyeOS eyeOS 0.9
-
eyeOS eyeOS-0.9.3-3.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-3.tar.gz?modtime=11 65836720&big_mirror=0 -
eyeOS eyeOS-0.9.3-4.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-4.tar.gz?modtime=11 65836720&big_mirror=0
eyeOS eyeOS 0.9.1
-
eyeOS eyeOS-0.9.3-3.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-3.tar.gz?modtime=11 65836720&big_mirror=0 -
eyeOS eyeOS-0.9.3-4.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-4.tar.gz?modtime=11 65836720&big_mirror=0
eyeOS eyeOS 0.9.3 -2a
-
eyeOS eyeOS-0.9.3-3.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-3.tar.gz?modtime=11 65836720&big_mirror=0 -
eyeOS eyeOS-0.9.3-4.tar.gz
http://downloads.sourceforge.net/eyeos/eyeOS-0.9.3-4.tar.gz?modtime=11 65836720&big_mirror=0
References
EyeOS Aplic.PHP Arbitrary File Upload Vulnerability
References:
References:
- 0.9.3-3 Release Note (EyeOS)
- eyeOS Homepage (eyeOS)