OpenForum 'saveAsAttachment()' Method Arbitrary File Creation Vulnerability
BID:40364
Info
OpenForum 'saveAsAttachment()' Method Arbitrary File Creation Vulnerability
| Bugtraq ID: | 40364 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 23 2010 12:00AM |
| Updated: | May 23 2010 12:00AM |
| Credit: | John Leitch |
| Vulnerable: |
Nicholas E.M Cross OpenForum 2.2 b005 |
| Not Vulnerable: | |
Discussion
OpenForum 'saveAsAttachment()' Method Arbitrary File Creation Vulnerability
OpenForum is prone to a vulnerability that may allow remote attackers to create arbitrary files on a vulnerable system.
Successful exploits will allow an attacker to create arbitrary files, which may then be executed to perform unauthorized actions. This may aid in further attacks.
OpenForum 2.2 b005 is vulnerable; other versions may also be affected.
OpenForum is prone to a vulnerability that may allow remote attackers to create arbitrary files on a vulnerable system.
Successful exploits will allow an attacker to create arbitrary files, which may then be executed to perform unauthorized actions. This may aid in further attacks.
OpenForum 2.2 b005 is vulnerable; other versions may also be affected.
Exploit / POC
OpenForum 'saveAsAttachment()' Method Arbitrary File Creation Vulnerability
An attacker can use readily available tools to exploit this issue.
The following proof of concept is available:
An attacker can use readily available tools to exploit this issue.
The following proof of concept is available:
Solution / Fix
OpenForum 'saveAsAttachment()' Method Arbitrary File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
OpenForum 'saveAsAttachment()' Method Arbitrary File Creation Vulnerability
References:
References:
- OpenForum Homepage (Google)