OpenX Arbitrary File Upload Vulnerability
BID:37110
Info
OpenX Arbitrary File Upload Vulnerability
| Bugtraq ID: | 37110 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 24 2009 12:00AM |
| Updated: | May 10 2010 10:32AM |
| Credit: | Moritz Naumann |
| Vulnerable: |
OpenX OpenX 2.8.1 OpenX OpenX 2.8 |
| Not Vulnerable: |
OpenX OpenX 2.8.2 |
Discussion
OpenX Arbitrary File Upload Vulnerability
OpenX is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately validate user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
The issue affects OpenX 2.8.1 and prior.
OpenX is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately validate user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
The issue affects OpenX 2.8.1 and prior.
Exploit / POC
OpenX Arbitrary File Upload Vulnerability
Attackers can exploit this issue via a browser.
A Metasploit exploit module is available.
Attackers can exploit this issue via a browser.
A Metasploit exploit module is available.
Solution / Fix
OpenX Arbitrary File Upload Vulnerability
Solution:
The vendor fixed this issue in OpenX 2.8.2. Please see the references for more information.
Solution:
The vendor fixed this issue in OpenX 2.8.2. Please see the references for more information.
References
OpenX Arbitrary File Upload Vulnerability
References:
References:
- OpenX 2.8.2 Release Notes (OpenX)
- OpenX Homepage (OpenX)
- Executing arbitrary PHP code on OpenX <= 2.8.1 (Moritz Naumann)