PivotX 'fileupload.php' CVE-2014-0342 Arbitrary File Upload Vulnerability
BID:66797
Info
PivotX 'fileupload.php' CVE-2014-0342 Arbitrary File Upload Vulnerability
| Bugtraq ID: | 66797 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0342 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2014 12:00AM |
| Updated: | Apr 11 2014 12:00AM |
| Credit: | Diego García |
| Vulnerable: |
PIVOTX PivotX 2.3.8 |
| Not Vulnerable: |
PIVOTX PivotX 2.3.9 |
Discussion
PivotX 'fileupload.php' CVE-2014-0342 Arbitrary File Upload Vulnerability
PivotX is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to properly check the file extensions.
An attacker can exploit this issue to upload arbitrary code and run it in the context of the web server process; other attacks are also possible.
PivotX 2.3.8 is vulnerable; other versions may also be affected.
PivotX is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to properly check the file extensions.
An attacker can exploit this issue to upload arbitrary code and run it in the context of the web server process; other attacks are also possible.
PivotX 2.3.8 is vulnerable; other versions may also be affected.
Exploit / POC
PivotX 'fileupload.php' CVE-2014-0342 Arbitrary File Upload Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
PivotX 'fileupload.php' CVE-2014-0342 Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.