MyRoom save_item.php Arbitrary File Upload Vulnerability
BID:6644
Info
MyRoom save_item.php Arbitrary File Upload Vulnerability
| Bugtraq ID: | 6644 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2003 12:00AM |
| Updated: | Jan 20 2003 12:00AM |
| Credit: | This vulnerability was reported by "Frog Man" <[email protected]>. |
| Vulnerable: |
MyRoom MyRoom 3.5 GOLD |
| Not Vulnerable: | |
Discussion
MyRoom save_item.php Arbitrary File Upload Vulnerability
A problem with MyRoom may make it possible for remote attackers to upload files to a vulnerable system.
Due to inadequate security checks performed by some PHP scripts, an attacker is able to upload arbitrary files to the system.
Given the ability to upload arbitrary files to the host, an attacker can exploit this vulnerability to upload malicious applications to the vulnerable system or use the system for the storage of files.
A problem with MyRoom may make it possible for remote attackers to upload files to a vulnerable system.
Due to inadequate security checks performed by some PHP scripts, an attacker is able to upload arbitrary files to the system.
Given the ability to upload arbitrary files to the host, an attacker can exploit this vulnerability to upload malicious applications to the vulnerable system or use the system for the storage of files.
Exploit / POC
MyRoom save_item.php Arbitrary File Upload Vulnerability
The following proof of concept was provided:
http://www.example.org/room/save_item.php?name=[NAME]&ref=test&photo=../inc/conf.php&photo_type=ttxt
The following proof of concept was provided:
http://www.example.org/room/save_item.php?name=[NAME]&ref=test&photo=../inc/conf.php&photo_type=ttxt
References
MyRoom save_item.php Arbitrary File Upload Vulnerability
References:
References:
- MyRoom Home Page (MyRoom)
- MyRoom (PHP) ("Frog Man"
)