Kwalbum <= 2.0.2 Arbitary File Upload Vulnerability

2008-12-21 / 2008-12-22
Risk: High
Local: No
Remote: Yes
CWE: CWE-20


CVSS Base Score: 7.1/10
Impact Subscore: 10/10
Exploitability Subscore: 3.9/10
Exploit range: Remote
Attack complexity: High
Authentication: Single time
Confidentiality impact: Complete
Integrity impact: Complete
Availability impact: Complete

========================================================== Kwalbum <= 2.0.2 Arbitrary file upload Vulnerabilities ========================================================== ,--^----------,--------,-----,-------^--, | ||||||||| `--------' | O .. CWH Underground Hacking Team .. `+---------------------------^----------| `\_,-------, _________________________| / XXXXXX /`| / / XXXXXX / `\ / / XXXXXX /\______( / XXXXXX / / XXXXXX / (________( `------' AUTHOR : CWH Underground DATE : 3 October 2008 SITE : cwh.citec.us ################################################################## APPLICATION : Kwalbum VERSION : <= 2.0.2 DOWNLOAD : http://downloads.sourceforge.net/kwalbum/kwalbum-2.0.2.zip ################################################################## ----------------- Description: ----------------- After registeration, you may obtain view, upload or admin permission. If you obtain an upload permission, you can upload php files which can access as a below example url. ----------- Exploit: ----------- [+] upload page: http://[target]/[path to kwalbum]/?p=UploadItems [+] exploit file format: http://[target]/[path to kwalbum]/[path to store image]/[year]/[month]/shell.php [+] exploit file example: http://[target]/[path to kwalbum]/items/08/10/shell.php ##################################################################### Greetz : ZeQ3uL, BAD $ectors, Snapter, Conan, JabAv0C, Win7dos #####################################################################

References:

http://xforce.iss.net/xforce/xfdb/45655
http://www.securityfocus.com/bid/31568
http://www.milw0rm.com/exploits/6664
http://secunia.com/advisories/32145


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top