|
Feeds -
Exploits
|
|
Written by osm@n
|
|
Monday, 23 February 2009 21:02 |
PHP-Nuke Book Catalog Module 'upload.php' Arbitrary File Upload Vulnerability
-\\Bugtraq ID: 19890
-\\Class: Input Validation Error
-\\CVE:
-\\Remote: Yes
-\\Local: No
-\\Published: Sep 07 2006 12:00AM
-\\Updated: Feb 23 2009 04:17PM
-\\Credit: osm@n is credited with the discovery of this vulnerability.
-\\Vulnerable: SAP Basis Community Book Catalog Module 1.0
-\\Discussion The Book Catalog module for PHP-Nuke is prone to a vulnerability that lets attackers upload arbitrary files.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
Book Catalog 1.0 is vulnerable; other versions may also be affected.
-\\Exploit(s)/PoC(s): An attacker can exploit this issue via a browser.
The following proof of concept is available:
=============================================================== 19890.html ^^^^^^^^^^^ http://www.example.com/modules/BookCatalog/upload.php
Upload c99 or r57 shell scripts
http://www.example.com/modules/BookCatalog/images/bookimg/c99safemod.php
-\\Solution Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at:
This e-mail address is being protected from spambots. You need JavaScript enabled to view it
.
-\\References(s) --Vendor Homepage http://www.basisconsultant.com/index.ph (SAP Basis Community)
|