RETIRED: Olate Download Arbitrary File Upload Vulnerability
BID:25509
Info
RETIRED: Olate Download Arbitrary File Upload Vulnerability
| Bugtraq ID: | 25509 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2007 12:00AM |
| Updated: | Sep 06 2007 06:01PM |
| Credit: | imei Addmimistrator is credited with the discovery of this vulnerability. |
| Vulnerable: |
Olate Download 3.4.2 |
| Not Vulnerable: | |
Discussion
RETIRED: Olate Download Arbitrary File Upload Vulnerability
Olate Download is prone to an arbitrary-file-upload vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue could allow an attacker to upload and execute arbitrary script code in the context of the affected webserver process. This may help the attacker compromise the application; other attacks are possible.
Olate Download 3.4.2 is vulnerable to this issue; other versions may also be affected.
NOTE: This BID is being retired because further information shows that the application is not vulnerable to this issue.
Olate Download is prone to an arbitrary-file-upload vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue could allow an attacker to upload and execute arbitrary script code in the context of the affected webserver process. This may help the attacker compromise the application; other attacks are possible.
Olate Download 3.4.2 is vulnerable to this issue; other versions may also be affected.
NOTE: This BID is being retired because further information shows that the application is not vulnerable to this issue.
Exploit / POC
RETIRED: Olate Download Arbitrary File Upload Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
RETIRED: Olate Download Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
NOTE: This BID is being retired because further information shows that the application is not vulnerable to this issue.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
NOTE: This BID is being retired because further information shows that the application is not vulnerable to this issue.
References
RETIRED: Olate Download Arbitrary File Upload Vulnerability
References:
References:
- Olate Download 3.4.2 ~ userupload.php ~ Upload Executable Files (imei Addmimistrator)
- Olate Download Homepage (Olate)
- Olate Download 3.4.2 ~ userupload.php ~ Upload Executable Files ("imei Addmimistrator"
) - Olate Download 3.4.2~uploads folder ~ directory traversal ("imei Addmimistrator"
)