AjaXplorer CVE-2013-5689 Arbitrary File Upload Vulnerability
BID:62259
Info
AjaXplorer CVE-2013-5689 Arbitrary File Upload Vulnerability
| Bugtraq ID: | 62259 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-5689 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2013 12:00AM |
| Updated: | Sep 05 2013 12:00AM |
| Credit: | Vikas Singhal |
| Vulnerable: |
AjaXplorer AjaXplorer 5.0.1 AjaXplorer AjaXplorer 4.0.4 AjaXplorer AjaXplorer 4.0.3 AjaXplorer AjaXplorer 4.0.2 AjaXplorer AjaXplorer 4.0.1 AjaXplorer AjaXplorer 3.2.5 AjaXplorer AjaXplorer 3.2.4 AjaXplorer AjaXplorer 3.1.1 AjaXplorer AjaXplorer 2.6.2 AjaXplorer AjaXplorer 2.6.1 AjaXplorer AjaXplorer 2.5.5 AjaXplorer AjaXplorer 2.5.3 AjaXplorer AjaXplorer 2.5.2 AjaXplorer AjaXplorer 5.0.2 AjaXplorer AjaXplorer 3.2 AjaXplorer AjaXplorer 2.6 |
| Not Vulnerable: |
AjaXplorer AjaXplorer 5.0.3 |
Discussion
AjaXplorer CVE-2013-5689 Arbitrary File Upload Vulnerability
AjaXplorer is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
AjaXplorer versions prior to 5.0.3 are vulnerable.
AjaXplorer is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
AjaXplorer versions prior to 5.0.3 are vulnerable.
Exploit / POC
AjaXplorer CVE-2013-5689 Arbitrary File Upload Vulnerability
An attacker can exploit this issue using a web browser.
The following example URI is available:
http://www.example.com/filemanagers/ajaxplorer/index.php?secure_token=[latest token]&get_action=upload&xhr_uploader=true&dir=/%00../%00../data/ HTTP/1.1
An attacker can exploit this issue using a web browser.
The following example URI is available:
http://www.example.com/filemanagers/ajaxplorer/index.php?secure_token=[latest token]&get_action=upload&xhr_uploader=true&dir=/%00../%00../data/ HTTP/1.1
Solution / Fix
AjaXplorer CVE-2013-5689 Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
AjaXplorer CVE-2013-5689 Arbitrary File Upload Vulnerability
References:
References:
- AjaXplorer Core 5.0.3 released (AjaXplorer)
- AjaXplorer Homepage (AjaXplorer)
- Multiple Vulnerabilities in ajaXplorer (Trustwave SpiderLabs)