Wiki Web Help 'uploadimage.php' Arbitrary File Upload Vulnerability
BID:41309
Info
Wiki Web Help 'uploadimage.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 41309 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2010 12:00AM |
| Updated: | Jul 05 2010 09:47PM |
| Credit: | John Leitch |
| Vulnerable: |
Richard Bondi Wiki Web Help 0.2.8 Richard Bondi Wiki Web Help 0.2.7 Richard Bondi Wiki Web Help 0.2.6 Richard Bondi Wiki Web Help 0.2.5 Richard Bondi Wiki Web Help 0.2.4 Richard Bondi Wiki Web Help 0.2.3 Richard Bondi Wiki Web Help 0.2.2 Richard Bondi Wiki Web Help 0.2.1 Richard Bondi Wiki Web Help 0.2 |
| Not Vulnerable: | |
Discussion
Wiki Web Help 'uploadimage.php' Arbitrary File Upload Vulnerability
Wiki Web Help is prone to an arbitrary-file-upload vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
Wiki Web Help 0.2.7 is vulnerable; other versions may also be affected.
Wiki Web Help is prone to an arbitrary-file-upload vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
Wiki Web Help 0.2.7 is vulnerable; other versions may also be affected.
Exploit / POC
Wiki Web Help 'uploadimage.php' Arbitrary File Upload Vulnerability
Attackers can exploit this issue via a web browser.
The following exploit is available :
Attackers can exploit this issue via a web browser.
The following exploit is available :
Solution / Fix
Wiki Web Help 'uploadimage.php' Arbitrary File Upload Vulnerability
Solution:
The vendor released a patch. Please see the references for more information.
Solution:
The vendor released a patch. Please see the references for more information.
References
Wiki Web Help 'uploadimage.php' Arbitrary File Upload Vulnerability
References:
References:
- Cross site scripting and arbitrary upload vulnerabilites - ID: 3025530 (Wiki Web Help)
- Wiki Web Help Project Page (Wiki Web Help)