VBZoom Arbitrary File Upload Vulnerability
BID:5926
Info
VBZoom Arbitrary File Upload Vulnerability
| Bugtraq ID: | 5926 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2002 12:00AM |
| Updated: | Oct 09 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to hish _ hish <[email protected]>. |
| Vulnerable: |
VBZoom VBZoom 1.0 1 |
| Not Vulnerable: | |
Discussion
VBZoom Arbitrary File Upload Vulnerability
It has been reported that VBZoom 1.01 may allow attackers to upload arbitrary files to a vulnerable system.
The vulnerability is the result of VBZoom failing to properly validate the types of files that are received. Validation is done through the use of JavaScript on the client side. An attacker can exploit this vulnerability by specifying an arbitrary file to be uploaded.
Given the ability to upload arbitrary files to the host, an attacker can exploit this vulnerability to upload malicious PHP scripts to the vulnerable system. Any malicious PHP files referenced will be executed in the security context of the site hosting VBZoom.
It has been reported that VBZoom 1.01 may allow attackers to upload arbitrary files to a vulnerable system.
The vulnerability is the result of VBZoom failing to properly validate the types of files that are received. Validation is done through the use of JavaScript on the client side. An attacker can exploit this vulnerability by specifying an arbitrary file to be uploaded.
Given the ability to upload arbitrary files to the host, an attacker can exploit this vulnerability to upload malicious PHP scripts to the vulnerable system. Any malicious PHP files referenced will be executed in the security context of the site hosting VBZoom.
Exploit / POC
VBZoom Arbitrary File Upload Vulnerability
The following proof of concept was provided:
http://www.victim.com/VBZooM/add-subject.php?Success=1
&FileName=SourceFile&FileName_size=500&FileName_name=DistFile
The following proof of concept was provided:
http://www.victim.com/VBZooM/add-subject.php?Success=1
&FileName=SourceFile&FileName_size=500&FileName_name=DistFile
Solution / Fix
VBZoom Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
VBZoom Arbitrary File Upload Vulnerability
References:
References: