Spaw Editor 'spawfm' Module Arbitrary File Upload Vulnerability
BID:40295
Info
Spaw Editor 'spawfm' Module Arbitrary File Upload Vulnerability
| Bugtraq ID: | 40295 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2010 12:00AM |
| Updated: | May 20 2010 12:00AM |
| Credit: | Ma3sTr0-Dz |
| Vulnerable: |
SOLMETRA SPAW PHP Editor 1.0.7 SOLMETRA SPAW PHP Editor 1.0.6 SOLMETRA SPAW PHP Editor 1.0.4 SOLMETRA SPAW PHP Editor 1.0.3 SOLMETRA SPAW PHP Editor 1.0.2 SOLMETRA SPAW PHP Editor 1.0.1 SOLMETRA SPAW PHP Editor 1.0 SOLMETRA SPAW Editor PHP Edition 2.0.8 1 SOLMETRA SPAW Editor PHP Edition 2.0.8 SOLMETRA SPAW Editor PHP Edition 2.0 SOLMETRA SPAW Editor .NET Edition 2.0 |
| Not Vulnerable: | |
Discussion
Spaw Editor 'spawfm' Module Arbitrary File Upload Vulnerability
Spaw Editor is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
The following are vulnerable:
Spaw Editor 1.0
Spaw Editor PHP Edition 2.0
Spaw Editor .NET Edition 2.0
Spaw Editor is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
The following are vulnerable:
Spaw Editor 1.0
Spaw Editor PHP Edition 2.0
Spaw Editor .NET Edition 2.0
Exploit / POC
Spaw Editor 'spawfm' Module Arbitrary File Upload Vulnerability
Attackers can exploit this issue via a browser.
The following example URIs are available:
http://www.example.com/spaw2/dialogs/dialog.aspx?module=spawfm&dialog=spawfm&theme=spaw2&lang=en&charset=utf-8&scid=2d0650b7920a4fbf87598f8d58b4a99b&type=images
http://www.example.com/spaw2/dialogs/dialog.php?module=spawfm&dialog=spawfm&theme=spaw2&lang=en&charset=utf-8&scid=2d0650b7920a4fbf87598f8d58b4a99b&type=files
Attackers can exploit this issue via a browser.
The following example URIs are available:
http://www.example.com/spaw2/dialogs/dialog.aspx?module=spawfm&dialog=spawfm&theme=spaw2&lang=en&charset=utf-8&scid=2d0650b7920a4fbf87598f8d58b4a99b&type=images
http://www.example.com/spaw2/dialogs/dialog.php?module=spawfm&dialog=spawfm&theme=spaw2&lang=en&charset=utf-8&scid=2d0650b7920a4fbf87598f8d58b4a99b&type=files
Solution / Fix
Spaw Editor 'spawfm' Module Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Spaw Editor 'spawfm' Module Arbitrary File Upload Vulnerability
References:
References:
- SPAW Editor Homepage (SOLMETRA)