BOLDfx eUploader 'admin.php' Multiple Remote Vulnerabilities
BID:41783
Info
BOLDfx eUploader 'admin.php' Multiple Remote Vulnerabilities
| Bugtraq ID: | 41783 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2009 12:00AM |
| Updated: | Dec 16 2009 12:00AM |
| Credit: | Milos Zivanovic |
| Vulnerable: |
BOLDfx Corp eUploader Pro 3.1.1 |
| Not Vulnerable: | |
Discussion
BOLDfx eUploader 'admin.php' Multiple Remote Vulnerabilities
BOLDfx eUploader is prone to multiple remote vulnerabilities, including a cross-site request-forgery vulnerability, a security-bypass vulnerability, and an HTML-injection vulnerability.
Attacker-supplied HTML and script code could run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user. A remote attacker may also be able to perform certain administrative actions without proper authentication; other attacks are also possible.
eUploader PRO 3.1.1 is vulnerable; other versions may also be affected.
BOLDfx eUploader is prone to multiple remote vulnerabilities, including a cross-site request-forgery vulnerability, a security-bypass vulnerability, and an HTML-injection vulnerability.
Attacker-supplied HTML and script code could run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user. A remote attacker may also be able to perform certain administrative actions without proper authentication; other attacks are also possible.
eUploader PRO 3.1.1 is vulnerable; other versions may also be affected.
Exploit / POC
BOLDfx eUploader 'admin.php' Multiple Remote Vulnerabilities
An attacker can use a browser to exploit these issues. In some cases, the attacker entices an unsuspecting user into following viewing a malicious web page.
The following example URI is available:
http://www.example.com/admin.php?delete=[ID]
The following example code is available:
An attacker can use a browser to exploit these issues. In some cases, the attacker entices an unsuspecting user into following viewing a malicious web page.
The following example URI is available:
http://www.example.com/admin.php?delete=[ID]
The following example code is available:
Solution / Fix
BOLDfx eUploader 'admin.php' Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
BOLDfx eUploader 'admin.php' Multiple Remote Vulnerabilities
References:
References:
- eUploader PRO - Homepage (BOLDfx)