YourPlace 1.0.2 Multiple Remote Vulnerabilities
BID:32971
Info
YourPlace 1.0.2 Multiple Remote Vulnerabilities
| Bugtraq ID: | 32971 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6770 CVE-2008-6771 CVE-2008-6772 CVE-2008-6773 CVE-2008-6769 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | Osirys |
| Vulnerable: |
YourPlace YourPlace 1.0.2 |
| Not Vulnerable: | |
Discussion
YourPlace 1.0.2 Multiple Remote Vulnerabilities
YourPlace is prone to multiple remote vulnerabilities:
- An arbitrary-file-upload vulnerability
- Multiple remote code-execution vulnerabilities
- A remote command-execution vulnerability
- A security-bypass vulnerability
Attackers can exploit these issues to upload and execute arbitrary PHP code within the context of the webserver, execute arbitrary commands, and gain unauthorized access to the affected application. Other attacks are also possible.
YourPlace 1.0.2 is vulnerable; other versions may also be affected.
YourPlace is prone to multiple remote vulnerabilities:
- An arbitrary-file-upload vulnerability
- Multiple remote code-execution vulnerabilities
- A remote command-execution vulnerability
- A security-bypass vulnerability
Attackers can exploit these issues to upload and execute arbitrary PHP code within the context of the webserver, execute arbitrary commands, and gain unauthorized access to the affected application. Other attacks are also possible.
YourPlace 1.0.2 is vulnerable; other versions may also be affected.
Exploit / POC
YourPlace 1.0.2 Multiple Remote Vulnerabilities
An attacker can exploit these issues through a browser.
The following exploits and proofs of concept are available:
An attacker can exploit these issues through a browser.
The following exploits and proofs of concept are available:
Solution / Fix
YourPlace 1.0.2 Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].