minb Multiple Arbitrary File Upload Vulnerabilities
BID:31127
Info
minb Multiple Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 31127 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-7005 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2008 12:00AM |
| Updated: | May 07 2015 05:24PM |
| Credit: | IRCRASH (R3d.W0rm (Sina Yazdanmehr)) |
| Vulnerable: |
minb minb 0.1 |
| Not Vulnerable: | |
Discussion
minb Multiple Arbitrary File Upload Vulnerabilities
The 'minb' program is prone to multiple vulnerabilities that allow remote attackers to upload and execute arbitrary script code on an affected computer with the privileges of the webserver process. The issues occur because the application fails to sanitize user-supplied input.
These issues affect minb 0.1.0; other versions may also be affected.
The 'minb' program is prone to multiple vulnerabilities that allow remote attackers to upload and execute arbitrary script code on an affected computer with the privileges of the webserver process. The issues occur because the application fails to sanitize user-supplied input.
These issues affect minb 0.1.0; other versions may also be affected.
Exploit / POC
minb Multiple Arbitrary File Upload Vulnerabilities
Attackers may exploit these issues via a browser.
The following exploit code is available:
Attackers may exploit these issues via a browser.
The following exploit code is available:
Solution / Fix
minb Multiple Arbitrary File Upload Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
minb Multiple Arbitrary File Upload Vulnerabilities
References:
References: