eFront Multiple Arbitrary File Upload Vulnerabilities
BID:31491
Info
eFront Multiple Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 31491 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-7026 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | Pepelux |
| Vulnerable: |
Epignosis eFront 3.5.1 |
| Not Vulnerable: | |
Discussion
eFront Multiple Arbitrary File Upload Vulnerabilities
eFront is prone to multiple vulnerabilities that allow remote attackers to upload and execute arbitrary script code on an affected computer with the privileges of the webserver process. The issues occur because the application fails to sanitize user-supplied input.
eFront 3.5.1 is vulnerable; other versions may also be affected.
eFront is prone to multiple vulnerabilities that allow remote attackers to upload and execute arbitrary script code on an affected computer with the privileges of the webserver process. The issues occur because the application fails to sanitize user-supplied input.
eFront 3.5.1 is vulnerable; other versions may also be affected.
Exploit / POC
eFront Multiple Arbitrary File Upload Vulnerabilities
Attackers may exploit these issues via a browser.
Attackers may exploit these issues via a browser.
Solution / Fix
eFront Multiple Arbitrary File Upload Vulnerabilities
Solution:
A vendor fix is available; please see the references for more information.
Epignosis eFront 3.5.1
Solution:
A vendor fix is available; please see the references for more information.
Epignosis eFront 3.5.1
-
Epignosis filesystem3.class.zip
http://forum.efrontlearning.net/download.php?id=91&sid=b00e87327e9251e 1180ff1f4cf230292
References
eFront Multiple Arbitrary File Upload Vulnerabilities
References:
References:
- eFront Homepage (Epignosis)
- Important security fix (periklis)
- Remote File Inclusion Vulnerability (Pepelux
)