ComingChina.com U-Mail 'edit.php' Arbitrary File Upload Vulnerability
BID:32013
Info
ComingChina.com U-Mail 'edit.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 32013 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4932 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2008 12:00AM |
| Updated: | Jan 11 2011 08:12AM |
| Credit: | Shennan Wang |
| Vulnerable: |
ComingChina.com U-Mail 4.9.1 |
| Not Vulnerable: | |
Discussion
ComingChina.com U-Mail 'edit.php' Arbitrary File Upload Vulnerability
ComingChina.com U-Mail is prone to a vulnerability that lets remote attackers upload and execute arbitrary script code on an affected computer with the privileges of the webserver process. The issue occurs because the application fails to sanitize user-supplied input.
U-Mail 4.9.1 is vulnerable; other versions may also be affected.
ComingChina.com U-Mail is prone to a vulnerability that lets remote attackers upload and execute arbitrary script code on an affected computer with the privileges of the webserver process. The issue occurs because the application fails to sanitize user-supplied input.
U-Mail 4.9.1 is vulnerable; other versions may also be affected.
Exploit / POC
ComingChina.com U-Mail 'edit.php' Arbitrary File Upload Vulnerability
Attackers may exploit this issue via a browser.
The following exploit code is available:
Attackers may exploit this issue via a browser.
The following exploit code is available:
Solution / Fix
ComingChina.com U-Mail 'edit.php' Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
ComingChina.com U-Mail 'edit.php' Arbitrary File Upload Vulnerability
References:
References: