ITheora 'download.php' Information Disclosure Vulnerability
BID:27788
Info
ITheora 'download.php' Information Disclosure Vulnerability
| Bugtraq ID: | 27788 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0797 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Ysangkok discovered this issue. |
| Vulnerable: |
IThora IThora 1.0rc1 |
| Not Vulnerable: |
IThora IThora 1.0rc2 |
Discussion
ITheora 'download.php' Information Disclosure Vulnerability
ITheora is prone to an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the webserver process. Information obtained may aid in further attacks.
ITheora 1.0rc1 is vulnerable; other versions may also be affected.
ITheora is prone to an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the webserver process. Information obtained may aid in further attacks.
ITheora 1.0rc1 is vulnerable; other versions may also be affected.
Exploit / POC
ITheora 'download.php' Information Disclosure Vulnerability
Attackers can exploit this vulnerability with a browser.
Attackers can exploit this vulnerability with a browser.
Solution / Fix
ITheora 'download.php' Information Disclosure Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
IThora IThora 1.0rc1
Solution:
The vendor released updates to address this issue. Please see the references for more information.
IThora IThora 1.0rc1
-
IThora itheora-v1.0rc2.tar.gz
http://menguy.aymeric.free.fr/theora/download/itheora-v1.0rc2.tar.gz
References
ITheora 'download.php' Information Disclosure Vulnerability
References:
References:
- IThora Homepage (IThora)
- Talk:Itheora (Ysangkok)