Website Baker 'upload.php' Arbitrary File Upload Vulnerability
BID:49185
Info
Website Baker 'upload.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 49185 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2011 12:00AM |
| Updated: | Aug 17 2011 12:00AM |
| Credit: | Aung Khant from YGN Ethical Hacker Group, Myanmar |
| Vulnerable: |
Website Baker Website Baker 2.8.1 Website Baker Website Baker 2.8 Website Baker Website Baker 2.6.5 Website Baker Website Baker 2.6.4 Website Baker Website Baker 2.6.1 Website Baker Website Baker 2.6 Website Baker Website Baker 2.5.2 |
| Not Vulnerable: |
Website Baker Website Baker 2.8.2 |
Discussion
Website Baker 'upload.php' Arbitrary File Upload Vulnerability
Website Baker is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Website Baker 2.8.1 and prior versions are vulnerable.
Website Baker is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Website Baker 2.8.1 and prior versions are vulnerable.
Exploit / POC
Website Baker 'upload.php' Arbitrary File Upload Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Website Baker 'upload.php' Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
Website Baker 'upload.php' Arbitrary File Upload Vulnerability
References:
References:
- Website Baker Homepage (Website Baker)
- WebsiteBaker 2.8.1 <= Arbitrary File Upload Vulnerability (YGN Ethical Hacker Group)