Avatar Studio PHP-Fusion Module Local File Include and Arbitrary File Upload Vulnerabilities
BID:37533
Info
Avatar Studio PHP-Fusion Module Local File Include and Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 37533 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 30 2009 12:00AM |
| Updated: | Dec 30 2009 09:52PM |
| Credit: | bonobug |
| Vulnerable: |
Terry Broullette Avatar Studio 2.02 |
| Not Vulnerable: | |
Discussion
Avatar Studio PHP-Fusion Module Local File Include and Arbitrary File Upload Vulnerabilities
The Avatar Studio mod for PHP-Fusion is prone to a local file-include vulnerability and an arbitrary-file-upload vulnerability.
An attacker can exploit these issues to upload arbitrary files onto the webserver, execute arbitrary local files within the context of the webserver, and obtain sensitive information.
The Avatar Studio mod for PHP-Fusion is prone to a local file-include vulnerability and an arbitrary-file-upload vulnerability.
An attacker can exploit these issues to upload arbitrary files onto the webserver, execute arbitrary local files within the context of the webserver, and obtain sensitive information.
Exploit / POC
Avatar Studio PHP-Fusion Module Local File Include and Arbitrary File Upload Vulnerabilities
An attacker can exploit these issues via a browser.
The following example data is available:
An attacker can exploit these issues via a browser.
The following example data is available:
Solution / Fix
Avatar Studio PHP-Fusion Module Local File Include and Arbitrary File Upload Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Avatar Studio PHP-Fusion Module Local File Include and Arbitrary File Upload Vulnerabilities
References:
References:
- Avatar Studio Homepage (Whisperwillows)
- PHP-Fusion Homepage (PHP-Fusion)