shiromuku(bu2)BBS CVE-2015-0868 Arbitrary File Creation Vulnerability
BID:72389
Info
shiromuku(bu2)BBS CVE-2015-0868 Arbitrary File Creation Vulnerability
| Bugtraq ID: | 72389 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-0868 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2015 12:00AM |
| Updated: | Jan 30 2015 12:00AM |
| Credit: | Shoji Baba |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
shiromuku(bu2)BBS CVE-2015-0868 Arbitrary File Creation Vulnerability
shiromuku(bu2)BBS is prone to an arbitrary-file-creation vulnerability.
An attacker can exploit this issue to create arbitrary files on the server and execute arbitrary code.
shiromuku(bu2)BBS 2.90 and prior are vulnerable.
shiromuku(bu2)BBS is prone to an arbitrary-file-creation vulnerability.
An attacker can exploit this issue to create arbitrary files on the server and execute arbitrary code.
shiromuku(bu2)BBS 2.90 and prior are vulnerable.
Exploit / POC
shiromuku(bu2)BBS CVE-2015-0868 Arbitrary File Creation Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
shiromuku(bu2)BBS CVE-2015-0868 Arbitrary File Creation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
shiromuku(bu2)BBS CVE-2015-0868 Arbitrary File Creation Vulnerability
References:
References: