PBlogEX Arbitrary File Upload and Authentication Bypass Vulnerabilities
BID:46760
Info
PBlogEX Arbitrary File Upload and Authentication Bypass Vulnerabilities
| Bugtraq ID: | 46760 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2011 12:00AM |
| Updated: | Mar 07 2011 12:00AM |
| Credit: | l3lack_lord |
| Vulnerable: |
TwelveDev PBlogEX 1.2 |
| Not Vulnerable: |
TwelveDev PBlogEX 1.2.1 |
Discussion
PBlogEX Arbitrary File Upload and Authentication Bypass Vulnerabilities
PBlogEX is prone to a vulnerability that lets remote attackers upload and execute arbitrary code because it fails to properly sanitize user-supplied files. The application is also prone to an authentication-bypass vulnerability.
An attacker can leverage these issues to execute arbitrary code on an affected computer with the privileges of the webserver process or to perform administrative actions without proper authentication.
Versions prior to PBlogEX 1.2.1 are vulnerable.
PBlogEX is prone to a vulnerability that lets remote attackers upload and execute arbitrary code because it fails to properly sanitize user-supplied files. The application is also prone to an authentication-bypass vulnerability.
An attacker can leverage these issues to execute arbitrary code on an affected computer with the privileges of the webserver process or to perform administrative actions without proper authentication.
Versions prior to PBlogEX 1.2.1 are vulnerable.
Exploit / POC
PBlogEX Arbitrary File Upload and Authentication Bypass Vulnerabilities
Attackers may exploit these issues with a browser.
Attackers may exploit these issues with a browser.
Solution / Fix
PBlogEX Arbitrary File Upload and Authentication Bypass Vulnerabilities
Solution:
The vendor released an update. Please the references for details.
Solution:
The vendor released an update. Please the references for details.
References
PBlogEX Arbitrary File Upload and Authentication Bypass Vulnerabilities
References:
References:
- PBlogEX Homepage (TwelveDev)