Ajax File and Image Manager 'ajax_file_upload.php' Arbitrary File Upload Vulnerability
BID:62514
Info
Ajax File and Image Manager 'ajax_file_upload.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 62514 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 19 2013 12:00AM |
| Updated: | Sep 19 2013 12:00AM |
| Credit: | Ilya Krupenko of Positive Technologies |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Ajax File and Image Manager 'ajax_file_upload.php' Arbitrary File Upload Vulnerability
Ajax File and Image Manager is prone to an arbitrary-file-upload vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to upload arbitrary PHP code and run it in the context of the Web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Ajax File and Image Manager 1.1 is vulnerable; other versions may also be affected.
Ajax File and Image Manager is prone to an arbitrary-file-upload vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to upload arbitrary PHP code and run it in the context of the Web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Ajax File and Image Manager 1.1 is vulnerable; other versions may also be affected.
References
Ajax File and Image Manager 'ajax_file_upload.php' Arbitrary File Upload Vulnerability
References:
References:
- Ajax File and Image Manager Homepage (phpletter)