Barbo91 upload.php Arbitrary File Upload Vulnerability
BID:25551
Info
Barbo91 upload.php Arbitrary File Upload Vulnerability
| Bugtraq ID: | 25551 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-4761 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | LordGroove is credited with the discovery of this vulnerability. |
| Vulnerable: |
Barbo91 barbo91 1.1 |
| Not Vulnerable: | |
Discussion
Barbo91 upload.php Arbitrary File Upload Vulnerability
Barbo91 is prone to an arbitrary-file-upload vulnerability because the application fails to verify the type of file being uploaded.
Exploiting this issue could allow an attacker to upload and execute arbitrary script code in the context of the affected webserver process.
This issue affects Barbo91 1.1; other versions may also be vulnerable.
Barbo91 is prone to an arbitrary-file-upload vulnerability because the application fails to verify the type of file being uploaded.
Exploiting this issue could allow an attacker to upload and execute arbitrary script code in the context of the affected webserver process.
This issue affects Barbo91 1.1; other versions may also be vulnerable.
Exploit / POC
Barbo91 upload.php Arbitrary File Upload Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
Barbo91 upload.php Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].