PBLang NTopic.PHP Arbitrary File Upload Vulnerability
BID:26559
Info
PBLang NTopic.PHP Arbitrary File Upload Vulnerability
| Bugtraq ID: | 26559 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 24 2007 12:00AM |
| Updated: | Nov 26 2007 04:24PM |
| Credit: | KiNgOfThEwOrLd is credited with the discovery of this vulnerability. |
| Vulnerable: |
PBLang PBLang 4.66 z PBLang PBLang 4.66 PBLang PBLang 4.65 PBLang PBLang 4.63 PBLang PBLang 4.56 (4.5 RC 2) PBLang PBLang 4.6 PBLang PBLang 4.0 PBLang PBLang 4.99.17.q PBLang PBLang 4.67.16.a |
| Not Vulnerable: | |
Discussion
PBLang NTopic.PHP Arbitrary File Upload Vulnerability
PBLang is prone to a vulnerability that lets attackers upload arbitrary code and execute it in the context of the webserver process. The issue occurs because the software fails to adequately sanitize user-supplied input.
A successful exploit may allow the attacker to gain unauthorized access or to escalate privileges; other attacks are also possible.
This issue affects PBLang 4.99.17.q; earlier versions may also be vulnerable.
PBLang is prone to a vulnerability that lets attackers upload arbitrary code and execute it in the context of the webserver process. The issue occurs because the software fails to adequately sanitize user-supplied input.
A successful exploit may allow the attacker to gain unauthorized access or to escalate privileges; other attacks are also possible.
This issue affects PBLang 4.99.17.q; earlier versions may also be vulnerable.
Exploit / POC
PBLang NTopic.PHP Arbitrary File Upload Vulnerability
Attackers may exploit this issue through a browser.
The following proof-of-concept examples are available:
Attackers may exploit this issue through a browser.
The following proof-of-concept examples are available:
Solution / Fix
PBLang NTopic.PHP Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
PBLang NTopic.PHP Arbitrary File Upload Vulnerability
References:
References: