The Uploader 'download_launch.php' Directory Traversal Vulnerability
BID:41020
Info
The Uploader 'download_launch.php' Directory Traversal Vulnerability
| Bugtraq ID: | 41020 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2010 12:00AM |
| Updated: | Jun 22 2010 12:00AM |
| Credit: | Xa7m3d |
| Vulnerable: |
The Uploader The Uploader 2.0.4 |
| Not Vulnerable: | |
Discussion
The Uploader 'download_launch.php' Directory Traversal Vulnerability
The Uploader is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
This issue affects version 2.0.4 of The Uploader.
The Uploader is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
This issue affects version 2.0.4 of The Uploader.
Exploit / POC
The Uploader 'download_launch.php' Directory Traversal Vulnerability
Attackers can exploit this issue through a browser.
The following example URI is available:
http://www.example.com/theuploader/api/download_launch.php?filename=../config.inc.php
Attackers can exploit this issue through a browser.
The following example URI is available:
http://www.example.com/theuploader/api/download_launch.php?filename=../config.inc.php
Solution / Fix
The Uploader 'download_launch.php' Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
The Uploader 'download_launch.php' Directory Traversal Vulnerability
References:
References:
- The Uploader Home Page (The Uploader)