phUploader 'phUploader.php' Arbitrary File Upload Vulnerability
BID:25405
Info
phUploader 'phUploader.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 25405 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-4527 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | Azad is credited with the discovery of this vulnerability. |
| Vulnerable: |
phphq.Net phUploader 1.2 |
| Not Vulnerable: |
phphq.Net phUploader 1.3 |
Discussion
phUploader 'phUploader.php' Arbitrary File Upload Vulnerability
phUploader is prone to an arbitrary-file-upload vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue could allow an attacker to upload and execute arbitrary script code in the context of the affected webserver process. This may help the attacker compromise the application; other attacks are possible.
Versions prior to phUploader 1.3 are vulnerable.
phUploader is prone to an arbitrary-file-upload vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue could allow an attacker to upload and execute arbitrary script code in the context of the affected webserver process. This may help the attacker compromise the application; other attacks are possible.
Versions prior to phUploader 1.3 are vulnerable.
Exploit / POC
phUploader 'phUploader.php' Arbitrary File Upload Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
phUploader 'phUploader.php' Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
phUploader 'phUploader.php' Arbitrary File Upload Vulnerability
References:
References:
- phphq.Net Homepage (phphq.Net)
- phUloader Homepage (phphq.Net)