Air Drive Plus Multiple Input Vallidation Vulnerabilities
BID:61081
Info
Air Drive Plus Multiple Input Vallidation Vulnerabilities
| Bugtraq ID: | 61081 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2013 12:00AM |
| Updated: | Jul 09 2013 12:00AM |
| Credit: | Benjamin Kunz Mejri |
| Vulnerable: |
Y.K. YING Air Drive Plus 2.4 |
| Not Vulnerable: | |
Discussion
Air Drive Plus Multiple Input Vallidation Vulnerabilities
Air Drive Plus is prone to multiple input validation vulnerabilities including a local file-include vulnerability, an arbitrary file-upload vulnerability, and an HTML-injection vulnerability.
An attacker can exploit these issues to upload arbitrary files onto the web server, execute arbitrary local files within the context of the web server, obtain sensitive information, execute arbitrary script code within the context of the browser, and steal cookie-based authentication credentials.
Air Drive Plus 2.4 is vulnerable; other versions may also be affected.
Air Drive Plus is prone to multiple input validation vulnerabilities including a local file-include vulnerability, an arbitrary file-upload vulnerability, and an HTML-injection vulnerability.
An attacker can exploit these issues to upload arbitrary files onto the web server, execute arbitrary local files within the context of the web server, obtain sensitive information, execute arbitrary script code within the context of the browser, and steal cookie-based authentication credentials.
Air Drive Plus 2.4 is vulnerable; other versions may also be affected.