WeBid 'converter.php' Multiple Remote PHP Code Injection Vulnerabilities
BID:48554
Info
WeBid 'converter.php' Multiple Remote PHP Code Injection Vulnerabilities
| Bugtraq ID: | 48554 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2011 12:00AM |
| Updated: | May 28 2012 09:50AM |
| Credit: | EgiX |
| Vulnerable: |
WeBid WeBid 1.0.2 |
| Not Vulnerable: | |
Discussion
WeBid 'converter.php' Multiple Remote PHP Code Injection Vulnerabilities
WeBid is prone to multiple vulnerabilities that attackers can leverage to execute arbitrary PHP code because the application fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected application and possibly the underlying computer.
WeBid 1.0.2 is vulnerable; other versions may also be affected.
WeBid is prone to multiple vulnerabilities that attackers can leverage to execute arbitrary PHP code because the application fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected application and possibly the underlying computer.
WeBid 1.0.2 is vulnerable; other versions may also be affected.
Exploit / POC
WeBid 'converter.php' Multiple Remote PHP Code Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following exploits are available:
Attackers can use a browser to exploit these issues.
The following exploits are available:
Solution / Fix
WeBid 'converter.php' Multiple Remote PHP Code Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
WeBid 'converter.php' Multiple Remote PHP Code Injection Vulnerabilities
References:
References:
- 1.0.2 Important security patches (WeBid)
- WeBid Homepage (WeBid)