phpBugTracker SQL Injection and Arbitrary File Upload Vulnerabilities
BID:42732
Info
phpBugTracker SQL Injection and Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 42732 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2010 12:00AM |
| Updated: | Aug 25 2010 12:00AM |
| Credit: | Secunia Research |
| Vulnerable: |
Benjamin Curtis phpBugTracker 1.0.5 |
| Not Vulnerable: | |
Discussion
phpBugTracker SQL Injection and Arbitrary File Upload Vulnerabilities
phpBugTracker is prone to an SQL-injection vulnerability and an arbitrary-file-upload vulnerability because it fails to sanitize user-supplied data.
Exploiting these issues could allow an attacker to compromise the application, execute arbitrary code, access or modify data, or exploit latent vulnerabilities in the underlying database.
phpBugTracker 1.0.5 is vulnerable; other versions may also be affected.
phpBugTracker is prone to an SQL-injection vulnerability and an arbitrary-file-upload vulnerability because it fails to sanitize user-supplied data.
Exploiting these issues could allow an attacker to compromise the application, execute arbitrary code, access or modify data, or exploit latent vulnerabilities in the underlying database.
phpBugTracker 1.0.5 is vulnerable; other versions may also be affected.
Exploit / POC
phpBugTracker SQL Injection and Arbitrary File Upload Vulnerabilities
An attacker can use a browser to exploit these issues.
An attacker can use a browser to exploit these issues.
Solution / Fix
phpBugTracker SQL Injection and Arbitrary File Upload Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
phpBugTracker SQL Injection and Arbitrary File Upload Vulnerabilities
References:
References:
- phpBugTracker - Download page (Benjamin Curtis)
- phpBugTracker - Homepage (Benjamin Curtis)
- Secunia Research: phpBugTracker "add_attachment()" Arbitrary File Upload (Secunia Research)
- Secunia Research: phpBugTracker "bugid" SQL Injection Vulnerability (Secunia Research)