Easy-Clanpage Arbitrary File Upload and Local File Include Vulnerabilities
BID:29707
Info
Easy-Clanpage Arbitrary File Upload and Local File Include Vulnerabilities
| Bugtraq ID: | 29707 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2818 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2008 12:00AM |
| Updated: | Apr 16 2015 05:59PM |
| Credit: | Loader007 |
| Vulnerable: |
Easy-Clanpage Easy-Clanpage 3.0 b1 |
| Not Vulnerable: | |
Discussion
Easy-Clanpage Arbitrary File Upload and Local File Include Vulnerabilities
Easy-Clanpage is prone to an arbitrary-file-upload vulnerability and a local file-include vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues to upload arbitrary files onto the webserver, execute arbitrary local files within the context of the webserver process, and obtain sensitive information. Successfully exploiting the vulnerabilities in tandem may allow the attacker to execute remote script code.
These issues affect Easy-Clanpage 3.0b1; other versions may also be vulnerable.
Easy-Clanpage is prone to an arbitrary-file-upload vulnerability and a local file-include vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues to upload arbitrary files onto the webserver, execute arbitrary local files within the context of the webserver process, and obtain sensitive information. Successfully exploiting the vulnerabilities in tandem may allow the attacker to execute remote script code.
These issues affect Easy-Clanpage 3.0b1; other versions may also be vulnerable.
Exploit / POC
Easy-Clanpage Arbitrary File Upload and Local File Include Vulnerabilities
An attacker can exploit this issue with a browser.
The following proof-of-concept URI is available:
http://www.example.com/path/?section=../path/to/image%00
An attacker can exploit this issue with a browser.
The following proof-of-concept URI is available:
http://www.example.com/path/?section=../path/to/image%00
Solution / Fix
Easy-Clanpage Arbitrary File Upload and Local File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Easy-Clanpage Arbitrary File Upload and Local File Include Vulnerabilities
References:
References:
- Easy-Clanpage Product Page (Easy-Clanpage)