WEBalbum 'photo_add.php' Security Bypass Vulnerability
BID:28280
Info
WEBalbum 'photo_add.php' Security Bypass Vulnerability
| Bugtraq ID: | 28280 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2008 12:00AM |
| Updated: | Mar 18 2008 06:10PM |
| Credit: | ZoRLu |
| Vulnerable: |
WEBalbum WEBalbum 2.0 |
| Not Vulnerable: | |
Discussion
WEBalbum 'photo_add.php' Security Bypass Vulnerability
WEBalbum is prone to a security-bypass vulnerability because the application fails to restrict access to certain webpages.
An attacker can exploit this issue to bypass certain security restrictions and upload arbitrary images to the affected webserver.
WEBalbum 2.0 is vulnerable; other versions may also be affected.
WEBalbum is prone to a security-bypass vulnerability because the application fails to restrict access to certain webpages.
An attacker can exploit this issue to bypass certain security restrictions and upload arbitrary images to the affected webserver.
WEBalbum 2.0 is vulnerable; other versions may also be affected.
Exploit / POC
WEBalbum 'photo_add.php' Security Bypass Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
Solution / Fix
WEBalbum 'photo_add.php' Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].