MyBB Plugin Uploader Arbitrary File Upload Vulnerability
BID:66109
Info
MyBB Plugin Uploader Arbitrary File Upload Vulnerability
| Bugtraq ID: | 66109 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 08 2014 12:00AM |
| Updated: | Mar 08 2014 12:00AM |
| Credit: | IRH |
| Vulnerable: |
MyBB Plugin Uploader 1.1.2 |
| Not Vulnerable: | |
Discussion
MyBB Plugin Uploader Arbitrary File Upload Vulnerability
The Plugin Uploader plugin for MyBB is prone to a vulnerability that lets attackers upload arbitrary files.
An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the web server process. This may facilitate unauthorized access or privilege escalation; other attacks may also possible.
Plugin Uploader 1.1.2 is vulnerable; other versions may also be affected.
The Plugin Uploader plugin for MyBB is prone to a vulnerability that lets attackers upload arbitrary files.
An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the web server process. This may facilitate unauthorized access or privilege escalation; other attacks may also possible.
Plugin Uploader 1.1.2 is vulnerable; other versions may also be affected.