Webify Photo Gallery Arbitrary File Deletion Vulnerability
BID:55512
Info
Webify Photo Gallery Arbitrary File Deletion Vulnerability
| Bugtraq ID: | 55512 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2012 12:00AM |
| Updated: | Sep 12 2012 12:00AM |
| Credit: | JiKo |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Webify Photo Gallery Arbitrary File Deletion Vulnerability
Webify Photo Gallery is prone to a vulnerability that lets attackers delete arbitrary files on an affected computer in the context of the web server.
Successful exploits may allow an attacker to delete uploaded files; this may aid in launching further attacks.
Webify Photo Gallery is prone to a vulnerability that lets attackers delete arbitrary files on an affected computer in the context of the web server.
Successful exploits may allow an attacker to delete uploaded files; this may aid in launching further attacks.
Exploit / POC
Webify Photo Gallery Arbitrary File Deletion Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/photogallery/uploads/X/
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/photogallery/uploads/X/
Solution / Fix
Webify Photo Gallery Arbitrary File Deletion Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Webify Photo Gallery Arbitrary File Deletion Vulnerability
References:
References: