UBBThreads/WWWThreads任意文件上传漏洞

漏洞信息详情

UBBThreads/WWWThreads任意文件上传漏洞

漏洞简介

Infopop UBB.Threads 5.4版本和Wired Community Software WWWThreads 5.0到5.0.9版本存在漏洞。远程攻击者通过使用可接受的扩展名但以另一扩展名结尾文件名上传任意文件。

漏洞公告

This issue has been addressed in UBBThreads versions 5.5 and later.
Information about upgrading can be found here:
http://www.infopop.com/support/ubbthreads/index.html

参考网址

来源: XF
名称: ubbthreads-file-upload(8022)
链接:http://www.iss.net/security_center/static/8022.php

来源: BUGTRAQ
名称: 20020130 [ WWWThreads, UBBThreads ] Security Hole in upload system
链接:http://online.securityfocus.com/archive/1/253172

来源: BID
名称: 3993
链接:http://www.securityfocus.com/bid/3993

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享