W2Box Arbitrary File Upload Vulnerability
BID:23975
Info
W2Box Arbitrary File Upload Vulnerability
| Bugtraq ID: | 23975 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-2742 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2007 12:00AM |
| Updated: | Apr 16 2015 06:15PM |
| Credit: | 4ur3v0ir is credited with the discovery of this vulnerability. |
| Vulnerable: |
labs.beffa.org w2box 4.0.0Beta4 |
| Not Vulnerable: | |
Discussion
W2Box Arbitrary File Upload Vulnerability
w2box is prone to an arbitrary-file-upload vulnerability.
An attacker can exploit this vulnerability to upload PHP script code and execute it in the context of the webserver process.
w2box 4.0.0Beta4 is vulnerable to this issue.
w2box is prone to an arbitrary-file-upload vulnerability.
An attacker can exploit this vulnerability to upload PHP script code and execute it in the context of the webserver process.
w2box 4.0.0Beta4 is vulnerable to this issue.
Exploit / POC
W2Box Arbitrary File Upload Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
W2Box Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
W2Box Arbitrary File Upload Vulnerability
References:
References:
- w2box Web Site (labs.beffa.org)
- ImI image file inclusion in script upload ([email protected])