eGroupWare Unspecified Arbitrary File Upload Vulnerability
BID:28817
Info
eGroupWare Unspecified Arbitrary File Upload Vulnerability
| Bugtraq ID: | 28817 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2041 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2008 12:00AM |
| Updated: | May 08 2008 02:15PM |
| Credit: | eGroupWare |
| Vulnerable: |
Gentoo Linux eGroupWare eGroupWare 1.4.3 eGroupWare eGroupWare 1.4.2 eGroupWare eGroupWare 1.4.1 |
| Not Vulnerable: |
eGroupWare eGroupWare 1.4.4 |
Discussion
eGroupWare Unspecified Arbitrary File Upload Vulnerability
eGroupWare is prone to a vulnerability that lets attackers upload arbitrary files. The issue stems from an unspecified error related to FCKEditor.
An attacker can exploit this vulnerability to upload files and execute arbitrary PHP script code in the context of the webserver process. This may aid in further attacks.
NOTE: This issue may be related to the FCKeditor vulnerability described in BID 25829. We will update this BID as more information emerges.
This issue affects versions prior to eGroupWare 1.4.004.
eGroupWare is prone to a vulnerability that lets attackers upload arbitrary files. The issue stems from an unspecified error related to FCKEditor.
An attacker can exploit this vulnerability to upload files and execute arbitrary PHP script code in the context of the webserver process. This may aid in further attacks.
NOTE: This issue may be related to the FCKeditor vulnerability described in BID 25829. We will update this BID as more information emerges.
This issue affects versions prior to eGroupWare 1.4.004.
Exploit / POC
eGroupWare Unspecified Arbitrary File Upload Vulnerability
Attackers will likely exploit this issue through a browser.
Attackers will likely exploit this issue through a browser.
Solution / Fix
eGroupWare Unspecified Arbitrary File Upload Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
eGroupWare Unspecified Arbitrary File Upload Vulnerability
References:
References:
- eGroupWare Homepage (eGroupWare)
- eGroupWare News (eGroupWare)