Kwalbum 'UploadItems' Parameter Arbitrary File Upload Vulnerability
BID:31568
Info
Kwalbum 'UploadItems' Parameter Arbitrary File Upload Vulnerability
| Bugtraq ID: | 31568 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5677 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2008 12:00AM |
| Updated: | Apr 16 2015 05:53PM |
| Credit: | CWH Underground |
| Vulnerable: |
Kwalbum Kwalbum 2.0.2 |
| Not Vulnerable: |
Kwalbum Kwalbum 2.1 |
Discussion
Kwalbum 'UploadItems' Parameter Arbitrary File Upload Vulnerability
Kwalbum is prone to a vulnerability that lets remote attackers upload and execute arbitrary script code on an affected computer with the privileges of the webserver process. The issue occurs because the application fails to sanitize user-supplied input.
Kwalbum 2.0.2 is vulnerable; other versions may also be affected.
Kwalbum is prone to a vulnerability that lets remote attackers upload and execute arbitrary script code on an affected computer with the privileges of the webserver process. The issue occurs because the application fails to sanitize user-supplied input.
Kwalbum 2.0.2 is vulnerable; other versions may also be affected.
Exploit / POC
Kwalbum 'UploadItems' Parameter Arbitrary File Upload Vulnerability
Attackers may exploit this issue via a browser.
The following example URI is available:
http://www.example.com/[path to kwalbum]/?p=UploadItems
Attackers may exploit this issue via a browser.
The following example URI is available:
http://www.example.com/[path to kwalbum]/?p=UploadItems
Solution / Fix
Kwalbum 'UploadItems' Parameter Arbitrary File Upload Vulnerability
Solution:
Reportedly, the issues are fixed in Kwalbum 2.1 and later. Please contact the vendor for more information.
Solution:
Reportedly, the issues are fixed in Kwalbum 2.1 and later. Please contact the vendor for more information.
References
Kwalbum 'UploadItems' Parameter Arbitrary File Upload Vulnerability
References:
References:
- Kwalbum Project Page (Kwalbum)