Papoo Upload Images Arbitrary File Upload Vulnerability
BID:36006
Info
Papoo Upload Images Arbitrary File Upload Vulnerability
| Bugtraq ID: | 36006 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2009 12:00AM |
| Updated: | Aug 21 2009 03:58PM |
| Credit: | RedTeam Pentesting GmbH |
| Vulnerable: |
Papoo Papoo 3.7.3 Papoo Papoo 3.7.2 Papoo Papoo 3.7.1 Papoo Papoo 3.7 Papoo Papoo 3.6.1 Papoo Papoo 3.6 Papoo Papoo 3.5 Papoo Papoo 3.02 Papoo Papoo 3.0 |
| Not Vulnerable: | |
Discussion
Papoo Upload Images Arbitrary File Upload Vulnerability
Papoo is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately validate user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Papoo is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately validate user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Exploit / POC
Papoo Upload Images Arbitrary File Upload Vulnerability
Attackers can exploit this issue via a browser.
The following command will generate a file with a valid GIF header that runs the 'phpinfo()' function when requested:
$ printf "GIF89a\x01\x00\x01\x00<?php phpinfo();?>" > poc.php
Attackers can exploit this issue via a browser.
The following command will generate a file with a valid GIF header that runs the 'phpinfo()' function when requested:
$ printf "GIF89a\x01\x00\x01\x00<?php phpinfo();?>" > poc.php
Solution / Fix
Papoo Upload Images Arbitrary File Upload Vulnerability
Solution:
The vendor has released a patch. Please see the references for details.
Papoo Papoo 3.5
Papoo Papoo 3.02
Papoo Papoo 3.0
Papoo Papoo 3.6
Papoo Papoo 3.6.1
Papoo Papoo 3.7
Papoo Papoo 3.7.1
Papoo Papoo 3.7.2
Papoo Papoo 3.7.3
Solution:
The vendor has released a patch. Please see the references for details.
Papoo Papoo 3.5
Papoo Papoo 3.02
Papoo Papoo 3.0
Papoo Papoo 3.6
Papoo Papoo 3.6.1
Papoo Papoo 3.7
Papoo Papoo 3.7.1
Papoo Papoo 3.7.2
Papoo Papoo 3.7.3
References
Papoo Upload Images Arbitrary File Upload Vulnerability
References:
References:
- Papoo CMS Homepage (Papoo)
- Papoo CMS: Authenticated Arbitrary Code Execution (RedTeam Pentesting GmbH)
- Papoo Sicherheitsmeldung - Juli 2009 (Papoo)
- [RT-SA-2009-005] Papoo CMS: Authenticated Arbitrary Code Execution (RedTeam Pentesting GmbH
)