PHP Fuzzer Framework Default Location Insecure Temporary File Creation Vulnerability
BID:35924
Info
PHP Fuzzer Framework Default Location Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 35924 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 03 2009 12:00AM |
| Updated: | Aug 21 2009 03:56PM |
| Credit: | Melissa Elliott |
| Vulnerable: |
Calcite PHP Fuzzer Framework 0 |
| Not Vulnerable: | |
Discussion
PHP Fuzzer Framework Default Location Insecure Temporary File Creation Vulnerability
PHP Fuzzer Framework creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to overwrite and execute arbitrary code with the privileges of the victim user. Successfully exploiting this issue may compromise the affected application and possibly the computer.
PHP Fuzzer Framework creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to overwrite and execute arbitrary code with the privileges of the victim user. Successfully exploiting this issue may compromise the affected application and possibly the computer.
Exploit / POC
PHP Fuzzer Framework Default Location Insecure Temporary File Creation Vulnerability
An attacker can use readily available commands to exploit the issue.
The following exploit is available:
An attacker can use readily available commands to exploit the issue.
The following exploit is available:
Solution / Fix
PHP Fuzzer Framework Default Location Insecure Temporary File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PHP Fuzzer Framework Default Location Insecure Temporary File Creation Vulnerability
References:
References:
- PHP Fuzzer Framework (Calcite)