HTTP File Upload ActiveX Control Arbitrary File and Directory Deletion Vulnerability
BID:28301
Info
HTTP File Upload ActiveX Control Arbitrary File and Directory Deletion Vulnerability
| Bugtraq ID: | 28301 |
| Class: | Design Error |
| CVE: |
CVE-2008-6638 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | t0pP8uZz |
| Vulnerable: |
VersalSoft HTTP File Upload 6.0 .35 |
| Not Vulnerable: | |
Discussion
HTTP File Upload ActiveX Control Arbitrary File and Directory Deletion Vulnerability
HTTP File Upload ActiveX Control is prone to a vulnerability that lets attackers delete arbitrary files or directories on affected computers. Successful attacks can result in denial-of-service conditions.
HTTP File Upload ActiveX Control 6.0.0.35 is vulnerable to this issue; other versions may also be affected.
NOTE: Further analysis indicates that the trial version of the ActiveX control ('UUploaderSvrD.dll' 6.0.0.35) is not marked 'safe for scripting', which makes it not vulnerable; versions installed with other installers may be marked safe. We will update this BID as more information emerges.
HTTP File Upload ActiveX Control is prone to a vulnerability that lets attackers delete arbitrary files or directories on affected computers. Successful attacks can result in denial-of-service conditions.
HTTP File Upload ActiveX Control 6.0.0.35 is vulnerable to this issue; other versions may also be affected.
NOTE: Further analysis indicates that the trial version of the ActiveX control ('UUploaderSvrD.dll' 6.0.0.35) is not marked 'safe for scripting', which makes it not vulnerable; versions installed with other installers may be marked safe. We will update this BID as more information emerges.
Exploit / POC
HTTP File Upload ActiveX Control Arbitrary File and Directory Deletion Vulnerability
Sample exploit code has been provided:
Sample exploit code has been provided:
Solution / Fix
HTTP File Upload ActiveX Control Arbitrary File and Directory Deletion Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
HTTP File Upload ActiveX Control Arbitrary File and Directory Deletion Vulnerability
References:
References:
- HTTP File Upload ActiveX Control Product Page (VersalSoft)
- Microsoft Knowledge Base Article 240797 (Microsoft)