Multiple AvailScript Products Arbitrary File Upload Vulnerabilities
BID:32821
Info
Multiple AvailScript Products Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 32821 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6900 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2008 12:00AM |
| Updated: | Aug 21 2009 06:43PM |
| Credit: | S.W.A.T. |
| Vulnerable: |
AvailScript Classmate Script 0 AvailScript Article Script 0 |
| Not Vulnerable: | |
Discussion
Multiple AvailScript Products Arbitrary File Upload Vulnerabilities
Multiple AvailScript Products are prone to multiple vulnerabilities that let remote attackers upload and execute arbitrary script code on an affected computer with the privileges of the webserver process. The issues occur because the applications fail to sanitize user-supplied input.
Multiple AvailScript Products are prone to multiple vulnerabilities that let remote attackers upload and execute arbitrary script code on an affected computer with the privileges of the webserver process. The issues occur because the applications fail to sanitize user-supplied input.
Exploit / POC
Multiple AvailScript Products Arbitrary File Upload Vulnerabilities
Attackers may exploit these issues via a browser.
Attackers may exploit these issues via a browser.
Solution / Fix
Multiple AvailScript Products Arbitrary File Upload Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple AvailScript Products Arbitrary File Upload Vulnerabilities
References:
References:
- AvailScript Article Script Homepage (AvailScript)
- Classmate Script Homepage (AvailScript)