Multiple phpstore.info Scripts Arbitrary File Upload Vulnerability
BID:32242
Info
Multiple phpstore.info Scripts Arbitrary File Upload Vulnerability
| Bugtraq ID: | 32242 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6928 CVE-2008-6929 CVE-2008-6930 CVE-2008-6931 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2008 12:00AM |
| Updated: | Aug 21 2009 03:57PM |
| Credit: | ZoRLu |
| Vulnerable: |
phpstore.info Real Estate 0 phpstore.info PHP Job Search 0 phpstore.info Complete Classifieds Script 0 phpstore.info Car Dealers 0 |
| Not Vulnerable: | |
Discussion
Multiple phpstore.info Scripts Arbitrary File Upload Vulnerability
Multiple phpstore.info scripts are prone to a vulnerability that lets remote attackers upload and execute arbitrary script code on an affected computer within the context of the webserver process. This issue occurs because the applications fail to validate user-supplied input.
The following phpshop.info products are vulnerable:
Car Dealers
PHP Job Search
Complete Classifieds Script
Real Estate
Multiple phpstore.info scripts are prone to a vulnerability that lets remote attackers upload and execute arbitrary script code on an affected computer within the context of the webserver process. This issue occurs because the applications fail to validate user-supplied input.
The following phpshop.info products are vulnerable:
Car Dealers
PHP Job Search
Complete Classifieds Script
Real Estate
Exploit / POC
Multiple phpstore.info Scripts Arbitrary File Upload Vulnerability
Attackers may exploit this issue via a browser.
Attackers may exploit this issue via a browser.
Solution / Fix
Multiple phpstore.info Scripts Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple phpstore.info Scripts Arbitrary File Upload Vulnerability
References:
References:
- Vendor Homepage (phpstore.info)