CMS from Scratch 'image.php' Directory Traversal and Arbitrary File Upload Vulnerabilities
BID:29434
Info
CMS from Scratch 'image.php' Directory Traversal and Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 29434 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 29 2008 12:00AM |
| Updated: | May 29 2008 12:00AM |
| Credit: | Stack |
| Vulnerable: |
CMS from Scratch CMS from Scratch 1.1.3 |
| Not Vulnerable: | |
Discussion
CMS from Scratch 'image.php' Directory Traversal and Arbitrary File Upload Vulnerabilities
CMS from Scratch is prone to a directory-traversal issue and an arbitrary-file-upload issue because the application fails to sanitize user-supplied input.
An attacker can leverage the directory-traversal issue to view and manipulate arbitrary directories with the privileges of the webserver process. The attacker can exploit the file-upload issue to upload files and execute arbitrary script code in the context of the webserver process.
CMS from Scratch 1.1.3 is vulnerable; other versions may also be affected.
CMS from Scratch is prone to a directory-traversal issue and an arbitrary-file-upload issue because the application fails to sanitize user-supplied input.
An attacker can leverage the directory-traversal issue to view and manipulate arbitrary directories with the privileges of the webserver process. The attacker can exploit the file-upload issue to upload files and execute arbitrary script code in the context of the webserver process.
CMS from Scratch 1.1.3 is vulnerable; other versions may also be affected.
Exploit / POC
CMS from Scratch 'image.php' Directory Traversal and Arbitrary File Upload Vulnerabilities
Attackers may exploit these issues through a browser.
The following example URI is available:
http://www.example.com/path/cms/images.php?dir=c:WINDOWS/system32/
Attackers may exploit these issues through a browser.
The following example URI is available:
http://www.example.com/path/cms/images.php?dir=c:WINDOWS/system32/
Solution / Fix
CMS from Scratch 'image.php' Directory Traversal and Arbitrary File Upload Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
CMS from Scratch 'image.php' Directory Traversal and Arbitrary File Upload Vulnerabilities
References:
References:
- CMS from Scratch Homepage (CMS from Scratch)