YingZhiPython Directory Traversal and Arbitrary File Upload Vulnerabilities
BID:55685
Info
YingZhiPython Directory Traversal and Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 55685 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2012 12:00AM |
| Updated: | Sep 26 2012 12:00AM |
| Credit: | Larry Cashdollar |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
YingZhiPython Directory Traversal and Arbitrary File Upload Vulnerabilities
YingZhiPython is prone to a directory-traversal vulnerability and an arbitrary file-upload vulnerability.
An attacker can exploit these issues to obtain sensitive information, to upload arbitrary code, and to run it in the context of the web server process.
YingZhiPython 1.9 is vulnerable; other versions may also be affected.
YingZhiPython is prone to a directory-traversal vulnerability and an arbitrary file-upload vulnerability.
An attacker can exploit these issues to obtain sensitive information, to upload arbitrary code, and to run it in the context of the web server process.
YingZhiPython 1.9 is vulnerable; other versions may also be affected.
Exploit / POC
YingZhiPython Directory Traversal and Arbitrary File Upload Vulnerabilities
An attacker can exploit these issues with a browser.
The following example URI is available:
ftp://www.example.com/../../../../../../../private/etc/passwd
An attacker can exploit these issues with a browser.
The following example URI is available:
ftp://www.example.com/../../../../../../../private/etc/passwd
Solution / Fix
YingZhiPython Directory Traversal and Arbitrary File Upload Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
YingZhiPython Directory Traversal and Arbitrary File Upload Vulnerabilities
References:
References: