PHPFileExchange File Upload Vulnerability
BID:3744
Info
PHPFileExchange File Upload Vulnerability
| Bugtraq ID: | 3744 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2001 12:00AM |
| Updated: | Aug 03 2001 12:00AM |
| Credit: | This vulnerability was first publicized in the PHPFileExchange changelog on August 3rd, 2001. |
| Vulnerable: |
PHPFileExchange PHPFileExchange 0.8.10 A PHPFileExchange PHPFileExchange 0.8.9 PHPFileExchange PHPFileExchange 0.8.8 Pre PHPFileExchange PHPFileExchange 0.8.7 Pre PHPFileExchange PHPFileExchange 0.8.6 Pre |
| Not Vulnerable: | |
Discussion
PHPFileExchange File Upload Vulnerability
PHPFileExchange is a freely available, open-source web-based file exchange system. It allows users to store files on a website and make them accessible to other users.
A problem exists in PHPFileExchange versions 0.8.10A which may allow a user to upload files to directories where they possess read-only privileges. For example, an attacker could upload a malicious file to another user's directory.
PHPFileExchange is a freely available, open-source web-based file exchange system. It allows users to store files on a website and make them accessible to other users.
A problem exists in PHPFileExchange versions 0.8.10A which may allow a user to upload files to directories where they possess read-only privileges. For example, an attacker could upload a malicious file to another user's directory.
Exploit / POC
PHPFileExchange File Upload Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
PHPFileExchange File Upload Vulnerability
Solution:
This vulnerability has been addressed in all versions later than PHPFileExchange 0.8.10A. Users are advised to upgrade to the latest version, which also features many other bug fixes.
PHPFileExchange PHPFileExchange 0.8.10 A
PHPFileExchange PHPFileExchange 0.8.6 Pre
PHPFileExchange PHPFileExchange 0.8.7 Pre
PHPFileExchange PHPFileExchange 0.8.8 Pre
PHPFileExchange PHPFileExchange 0.8.9
Solution:
This vulnerability has been addressed in all versions later than PHPFileExchange 0.8.10A. Users are advised to upgrade to the latest version, which also features many other bug fixes.
PHPFileExchange PHPFileExchange 0.8.10 A
-
PHPFileExchange latest.tar.gz
http://www.seattleserver.com/Projects/phphttpfs/latest.tar.gz
PHPFileExchange PHPFileExchange 0.8.6 Pre
-
PHPFileExchange latest.tar.gz
http://www.seattleserver.com/Projects/phphttpfs/latest.tar.gz
PHPFileExchange PHPFileExchange 0.8.7 Pre
-
PHPFileExchange latest.tar.gz
http://www.seattleserver.com/Projects/phphttpfs/latest.tar.gz
PHPFileExchange PHPFileExchange 0.8.8 Pre
-
PHPFileExchange latest.tar.gz
http://www.seattleserver.com/Projects/phphttpfs/latest.tar.gz
PHPFileExchange PHPFileExchange 0.8.9
-
PHPFileExchange latest.tar.gz
http://www.seattleserver.com/Projects/phphttpfs/latest.tar.gz