Interspire Knowledge Manager 'callback.snipshot.php' Arbitrary File Creation Vulnerability
BID:38186
Info
Interspire Knowledge Manager 'callback.snipshot.php' Arbitrary File Creation Vulnerability
| Bugtraq ID: | 38186 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 03 2010 12:00AM |
| Updated: | Feb 03 2010 12:00AM |
| Credit: | Cory Marsh |
| Vulnerable: |
Interspire Knowledge Manager 5.1.3 Interspire Knowledge Manager 5.1.3 Interspire Knowledge Manager 5.1.2 Interspire Knowledge Manager 5 |
| Not Vulnerable: | |
Discussion
Interspire Knowledge Manager 'callback.snipshot.php' Arbitrary File Creation Vulnerability
Interspire Knowledge Manager is prone to a vulnerability that allows attackers to create arbitrary files on a vulnerable computer.
An attacker may exploit this issue to create arbitrary files, which may then be executed to perform unauthorized actions. This may aid in further attacks.
Knowledge Manager 5.1.3 is vulnerable; other versions may also be affected.
Interspire Knowledge Manager is prone to a vulnerability that allows attackers to create arbitrary files on a vulnerable computer.
An attacker may exploit this issue to create arbitrary files, which may then be executed to perform unauthorized actions. This may aid in further attacks.
Knowledge Manager 5.1.3 is vulnerable; other versions may also be affected.
Exploit / POC
Interspire Knowledge Manager 'callback.snipshot.php' Arbitrary File Creation Vulnerability
Attackers can use readily available tools to exploit this issue.
The following proof of concept is available:
Attackers can use readily available tools to exploit this issue.
The following proof of concept is available:
Solution / Fix
Interspire Knowledge Manager 'callback.snipshot.php' Arbitrary File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Interspire Knowledge Manager 'callback.snipshot.php' Arbitrary File Creation Vulnerability
References:
References:
- Interspire Homepage (Interspire)
- Interspire Knowledge Manager multiple remote code execution vulnerabilities (Cory Marsh)