BigACE Multiple Arbitrary File Upload Vulnerabilities
BID:47090
Info
BigACE Multiple Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 47090 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 30 2011 12:00AM |
| Updated: | Apr 18 2011 10:14AM |
| Credit: | Net.Edit0r, KedAns-Dz |
| Vulnerable: |
BigACE BigACE 2.7.5 |
| Not Vulnerable: | |
Discussion
BigACE Multiple Arbitrary File Upload Vulnerabilities
BigACE is prone to multiple arbitrary-file-upload vulnerabilities because the application fails to adequately sanitize user-supplied input.
An attacker can exploit these issues to upload arbitrary code and run it in the context of the affected application.
BigACE 2.7.5 is vulnerable; other versions may also be affected.
BigACE is prone to multiple arbitrary-file-upload vulnerabilities because the application fails to adequately sanitize user-supplied input.
An attacker can exploit these issues to upload arbitrary code and run it in the context of the affected application.
BigACE 2.7.5 is vulnerable; other versions may also be affected.
Exploit / POC
BigACE Multiple Arbitrary File Upload Vulnerabilities
Attackers can exploit these issues using a browser.
Attackers can exploit these issues using a browser.
Solution / Fix
BigACE Multiple Arbitrary File Upload Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
BigACE Multiple Arbitrary File Upload Vulnerabilities
References:
References:
- BigACE 2.7.5 (BigACE)
- BigACE Homepage (BigACE)