Chyrp SQL Injection and Arbitrary File Upload Vulnerabilities
BID:54421
Info
Chyrp SQL Injection and Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 54421 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2012 12:00AM |
| Updated: | Jul 13 2012 12:00AM |
| Credit: | KedAns-Dz. |
| Vulnerable: |
Chyrp Chyrp 2.1.2 |
| Not Vulnerable: | |
Discussion
Chyrp SQL Injection and Arbitrary File Upload Vulnerabilities
Chyrp is prone to an SQL-injection vulnerability and an arbitrary-file-upload vulnerability because it fails to sanitize user-supplied data.
Exploiting these issues could allow attackers to compromise the application, to execute arbitrary code, to access or modify data, or to exploit latent vulnerabilities in the underlying database.
Chyrp 2.1.2 is vulnerable; other versions may also be affected.
Chyrp is prone to an SQL-injection vulnerability and an arbitrary-file-upload vulnerability because it fails to sanitize user-supplied data.
Exploiting these issues could allow attackers to compromise the application, to execute arbitrary code, to access or modify data, or to exploit latent vulnerabilities in the underlying database.
Chyrp 2.1.2 is vulnerable; other versions may also be affected.
Exploit / POC
Chyrp SQL Injection and Arbitrary File Upload Vulnerabilities
An attacker can use a browser to exploit these issues.
An attacker can use a browser to exploit these issues.
Solution / Fix
Chyrp SQL Injection and Arbitrary File Upload Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].