Webify Blog Arbitrary File Deletion Vulnerability
BID:55496
Info
Webify Blog Arbitrary File Deletion Vulnerability
| Bugtraq ID: | 55496 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2012 12:00AM |
| Updated: | Sep 11 2012 12:00AM |
| Credit: | JiKo |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Webify Blog Arbitrary File Deletion Vulnerability
Webify Blog is prone to a vulnerability that lets attackers delete arbitrary files on an affected computer in the context of the web server.
Successful exploits may allow an attacker to delete files uploaded in a blog post; this may aid in launching further attacks.
Webify Blog is prone to a vulnerability that lets attackers delete arbitrary files on an affected computer in the context of the web server.
Successful exploits may allow an attacker to delete files uploaded in a blog post; this may aid in launching further attacks.
Exploit / POC
Webify Blog Arbitrary File Deletion Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/blog/uploads/X/
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/blog/uploads/X/
Solution / Fix
Webify Blog Arbitrary File Deletion Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].