NetEase Ruby Programming Language for iOS Arbitrary File Upload Vulnerability
BID:62355
Info
NetEase Ruby Programming Language for iOS Arbitrary File Upload Vulnerability
| Bugtraq ID: | 62355 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2013 12:00AM |
| Updated: | Sep 12 2013 12:00AM |
| Credit: | Larry W. Cashdollar |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
NetEase Ruby Programming Language for iOS Arbitrary File Upload Vulnerability
NetEase Ruby Programming Language for iOS is prone to an arbitrary file-upload vulnerability because it fails to properly validate the request.
An attacker may leverage this issue to upload arbitrary files without requiring authentication in the context of the affected application. This may lead to further attacks.
NetEase Ruby Programming Language for iOS 1.7 is vulnerable; other versions may also be affected.
NetEase Ruby Programming Language for iOS is prone to an arbitrary file-upload vulnerability because it fails to properly validate the request.
An attacker may leverage this issue to upload arbitrary files without requiring authentication in the context of the affected application. This may lead to further attacks.
NetEase Ruby Programming Language for iOS 1.7 is vulnerable; other versions may also be affected.
Exploit / POC
NetEase Ruby Programming Language for iOS Arbitrary File Upload Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
NetEase Ruby Programming Language for iOS Arbitrary File Upload Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
NetEase Ruby Programming Language for iOS Arbitrary File Upload Vulnerability
References:
References:
- NetEase Homepage (NetEase)
- NetEase Ruby Programming Language for iOS (XiaoWen Huang)
- Unauthenticated Remote File Upload via HTTP for ruby-Programming language 1.7 on (Larry W. Cashdollar)