AuraCMS mod/contak.php Arbitrary File Upload Vulnerability
BID:25621
Info
AuraCMS mod/contak.php Arbitrary File Upload Vulnerability
| Bugtraq ID: | 25621 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-4905 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | k1tk4t is credited with the discovery of this vulnerability. |
| Vulnerable: |
auraCMS Aura CMS 2.1 |
| Not Vulnerable: | |
Discussion
AuraCMS mod/contak.php Arbitrary File Upload Vulnerability
AuraCMS is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify the type of file being uploaded.
Exploiting this issue could allow attackers to upload and execute arbitrary script code in the context of the affected webserver process.
This issue affects AuraCMS 2.1; other versions may also be vulnerable.
AuraCMS is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify the type of file being uploaded.
Exploiting this issue could allow attackers to upload and execute arbitrary script code in the context of the affected webserver process.
This issue affects AuraCMS 2.1; other versions may also be vulnerable.
Exploit / POC
AuraCMS mod/contak.php Arbitrary File Upload Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
AuraCMS mod/contak.php Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
AuraCMS mod/contak.php Arbitrary File Upload Vulnerability
References:
References:
- AuraCMS 2.1 - Remote File Attachment - Local File Inclusion (k1tk4t)
- AuraCMS Homepage (AuraCMS)