MauryCMS Unspecified Arbitrary File Upload Vulnerability
BID:32439
Info
MauryCMS Unspecified Arbitrary File Upload Vulnerability
| Bugtraq ID: | 32439 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6951 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 23 2008 12:00AM |
| Updated: | Aug 25 2009 10:12PM |
| Credit: | RoMaNcYxHaCkEr |
| Vulnerable: |
MauryCMS MauryCMS 0.53.2 |
| Not Vulnerable: | |
Discussion
MauryCMS Unspecified Arbitrary File Upload Vulnerability
MauryCMS is prone to an unspecified vulnerability that lets attackers upload arbitrary files. The issue occurs because application fails to adequately sanitize user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
This issue affects MauryCMS 0.53.2 and earlier versions.
MauryCMS is prone to an unspecified vulnerability that lets attackers upload arbitrary files. The issue occurs because application fails to adequately sanitize user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
This issue affects MauryCMS 0.53.2 and earlier versions.
Exploit / POC
MauryCMS Unspecified Arbitrary File Upload Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
MauryCMS Unspecified Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].