Pakupaku CMS Index.PHP Arbitrary File Upload Vulnerability
BID:25491
Info
Pakupaku CMS Index.PHP Arbitrary File Upload Vulnerability
| Bugtraq ID: | 25491 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-4640 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | Gold_M is credited with the discovery of this vulnerability. |
| Vulnerable: |
Pakupaku CMS Pakupaku CMS 0.4 |
| Not Vulnerable: | |
Discussion
Pakupaku CMS Index.PHP Arbitrary File Upload Vulnerability
Pakupaku CMS is prone to an arbitrary file-upload vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue could allow an attacker to upload and execute arbitrary script code in the context of the affected webserver process. This may help the attacker compromise the application; other attacks are possible.
Pakupaku CMS 0.4 is vulnerable; other versions may also be affected.
Pakupaku CMS is prone to an arbitrary file-upload vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue could allow an attacker to upload and execute arbitrary script code in the context of the affected webserver process. This may help the attacker compromise the application; other attacks are possible.
Pakupaku CMS 0.4 is vulnerable; other versions may also be affected.
Exploit / POC
Pakupaku CMS Index.PHP Arbitrary File Upload Vulnerability
Attackers may exploit this issue through a browser.
The following exploit code is available:
Attackers may exploit this issue through a browser.
The following exploit code is available:
Solution / Fix
Pakupaku CMS Index.PHP Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Pakupaku CMS Index.PHP Arbitrary File Upload Vulnerability
References:
References:
- Project Homepage (Pakupaku CMS)