Simple E-Document 'upload.php' Arbitrary File Upload Vulnerability
BID:65175
Info
Simple E-Document 'upload.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 65175 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2014 12:00AM |
| Updated: | Feb 04 2014 01:06AM |
| Credit: | vinicius777 and Brendan Coles |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Simple E-Document 'upload.php' Arbitrary File Upload Vulnerability
Simple E-Document is prone to an arbitrary-file-upload vulnerability because it fails to adequately sanitize user-supplied input.
An authenticated attacker may leverage this issue to upload arbitrary files; this can result in arbitrary code execution within the context of the vulnerable application.
Simple E-Document 1.31 is vulnerable; other versions may also be affected.
Simple E-Document is prone to an arbitrary-file-upload vulnerability because it fails to adequately sanitize user-supplied input.
An authenticated attacker may leverage this issue to upload arbitrary files; this can result in arbitrary code execution within the context of the vulnerable application.
Simple E-Document 1.31 is vulnerable; other versions may also be affected.
Exploit / POC
Simple E-Document 'upload.php' Arbitrary File Upload Vulnerability
An attacker can exploit this issue using browser or ready available tools.
An attacker can exploit this issue using browser or ready available tools.
Solution / Fix
Simple E-Document 'upload.php' Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Simple E-Document 'upload.php' Arbitrary File Upload Vulnerability
References:
References: