Editor Login | Register
Ekle

> World > Security
DotClear ecrire/images.php File Upload Vulnerability - Security - World -
CWRedLight
(Date : 16.04.2008 22:00:10)


DotClear ecrire/images.php File Upload Vulnerability
Secunia Advisory: SA29819  
Release Date: 2008-04-16

Critical:
Less critical
Impact: System access
Where: From remote
Solution Status: Unpatched

Software:DotClear 1.x
Description:
Morgan ARMAND has discovered a vulnerability in DotClear, which can be exploited by malicious users to compromise a vulnerable system.

The ecrire/images.php script fails to validate the extension of an uploaded file. This can be exploited to upload files with the ".php" extension and execute arbitrary PHP code on the server, by creating a file that is both a syntactically correct PHP script and an image that the PHP function getimagesize() considers correct.

Successful exploitation requires valid advanced editor or administrator credentials, and having set write permissions on the "images/" directory.

The vulnerability is confirmed in version 1.2.7.1. Other versions may also be affected.

Solution:
Only grant advanced editor or administrator access to trusted users.

Remove write permissions from the "images/" directory.

Provided and/or discovered by:
Morgan ARMAND


Derecelendir
Kaynak http://secunia.com/advisories/29819/
İçerik İhbarı
Bağlantılar: bilgininefendisi.net

Open Source Document Project AUP&TOS