GalaxyScripts Mini File Host 'upload.php' Local File Include Vulnerability
BID:27327
Info
GalaxyScripts Mini File Host 'upload.php' Local File Include Vulnerability
| Bugtraq ID: | 27327 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0357 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 17 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Scary-Boys discovered this vulnerability. |
| Vulnerable: |
Galaxyscripts Mini File Host 1.2 |
| Not Vulnerable: | |
Discussion
GalaxyScripts Mini File Host 'upload.php' Local File Include Vulnerability
GalaxyScripts Mini File Host is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue to execute arbitrary local scripts and retrieve potentially sensitive information.
This issue affects Mini File Host 1.2 and prior versions.
GalaxyScripts Mini File Host is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue to execute arbitrary local scripts and retrieve potentially sensitive information.
This issue affects Mini File Host 1.2 and prior versions.
Exploit / POC
GalaxyScripts Mini File Host 'upload.php' Local File Include Vulnerability
An attacker can exploit this issue with a browser.
The following proof-of-concept URI is available:
http://ww.example.com/pages/upload.php?language=[Local Script]
An attacker can exploit this issue with a browser.
The following proof-of-concept URI is available:
http://ww.example.com/pages/upload.php?language=[Local Script]
Solution / Fix
GalaxyScripts Mini File Host 'upload.php' Local File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
GalaxyScripts Mini File Host 'upload.php' Local File Include Vulnerability
References:
References:
- Mini File Host 1.2 Released (GalaxyScripts)