Peaches Posted December 29, 2008 Report Share Posted December 29, 2008 phpEmployment File Upload Vulnerability Release Date: 2008-12-26 Critical: Highly Impact: System access Where: From remote Solution Status: Unpatched Software:phpEmployment 1.x Subscribe: Instant alerts on relevant vulnerabilities Description: ahmadbady has discovered a vulnerability in phpEmployment, which can be exploited by malicious people to compromise a vulnerable system. This vulnerability is caused due to the auth.php script failing to validate the types of uploaded images. This can be exploited to upload files with arbitrary extensions (e.g. ".php") and execute arbitrary PHP code on the server. This vulnerability is confirmed in version 1.8. Other versions may also be affected. Solution: Edit the source code to ensure that input is properly verified. Provided and/or discovered by: ahmadbady Original Advisory: http://milw0rm.com/exploits/7563 Secunia Advisories: http://secunia.com/advisories/33268/ Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.