PHP-Nuke mailattach.php Remote File Upload Vulnerability
BID:8764
Info
PHP-Nuke mailattach.php Remote File Upload Vulnerability
| Bugtraq ID: | 8764 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 04 2003 12:00AM |
| Updated: | Oct 04 2003 12:00AM |
| Credit: | Discovery is credited to Frog Man <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 6.7 |
| Not Vulnerable: | |
Discussion
PHP-Nuke mailattach.php Remote File Upload Vulnerability
The PHP-Nuke mailattach.php script does not properly filter input, potentially allowing files to be uploaded to the system outside the webroot. By including directory traversal characters with the filename to upload, an attacker could possibly overwrite other files on the system or save malicious files to sensitive locations.
The PHP-Nuke mailattach.php script does not properly filter input, potentially allowing files to be uploaded to the system outside the webroot. By including directory traversal characters with the filename to upload, an attacker could possibly overwrite other files on the system or save malicious files to sensitive locations.