SeedDMS Multiple Unspecified Arbitrary File Upload Vulnerabilities
BID:66409
Info
SeedDMS Multiple Unspecified Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 66409 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 25 2014 12:00AM |
| Updated: | Mar 25 2014 12:00AM |
| Credit: | Steven Seeley |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
SeedDMS Multiple Unspecified Arbitrary File Upload Vulnerabilities
SeedDMS is prone to multiple unspecified vulnerabilities that let attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.
An attacker may leverage these issues to upload arbitrary files to the affected computer; this can result in an arbitrary PHP code execution within the context of the affected site.
Versions prior to SeedDMS 4.3.7 are vulnerable.
SeedDMS is prone to multiple unspecified vulnerabilities that let attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.
An attacker may leverage these issues to upload arbitrary files to the affected computer; this can result in an arbitrary PHP code execution within the context of the affected site.
Versions prior to SeedDMS 4.3.7 are vulnerable.
Exploit / POC
SeedDMS Multiple Unspecified Arbitrary File Upload Vulnerabilities
An attacker can exploit these issues using a web browser.
An attacker can exploit these issues using a web browser.
Solution / Fix
SeedDMS Multiple Unspecified Arbitrary File Upload Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SeedDMS Multiple Unspecified Arbitrary File Upload Vulnerabilities
References:
References: