TikiWiki未授权文件上传漏洞

漏洞信息详情

TikiWiki未授权文件上传漏洞

漏洞简介

TikiWiki 1.8.4.1以前的版本没有正确核实上传的图像,远程攻击者可以上传和执行任意PHP脚本,该漏洞不同于CVE-2005-0200。

漏洞公告

Gentoo has released an advisory to provide updates for this issue. Updates may be applied by running the following commands as the superuser:
emerge –sync
emerge –ask –oneshot –verbose “>=www-apps/tikiwiki-1.8.4.1”
This issue has been addressed in releases 1.7.9, 1.8.5, and 1.9-rc3.1.
TikiWiki Project TikiWiki 1.7.1 .1

TikiWiki Project TikiWiki 1.7.2

TikiWiki Project TikiWiki 1.7.3

TikiWiki Project TikiWiki 1.7.4

TikiWiki Project TikiWiki 1.7.5

TikiWiki Project TikiWiki 1.7.6

TikiWiki Project TikiWiki 1.7.7

TikiWiki Project TikiWiki 1.7.8

TikiWiki Project TikiWiki 1.8

TikiWiki Project TikiWiki 1.8.1

TikiWiki Project TikiWiki 1.8.2

TikiWiki Project TikiWiki 1.8.3

TikiWiki Project TikiWiki 1.8.4

TikiWiki Project TikiWiki 1.9 -rc3

TikiWiki Project TikiWiki 1.9 -rc2

TikiWiki Project TikiWiki 1.9 -rc1

参考网址

来源: BID
名称: 12110
链接:http://www.securityfocus.com/bid/12110

来源: GENTOO
名称: GLSA-200501-12
链接:http://www.gentoo.org/security/en/glsa/glsa-200501-12.xml

来源: tikiwiki.org
链接:http://tikiwiki.org/tiki-read_article.php?articleId=97

来源: XF
名称: tikiwiki-image-command-execution(18691)
链接:http://xforce.iss.net/xforce/xfdb/18691

来源: CIAC
名称: P-084
链接:http://www.ciac.org/ciac/bulletins/p-084.shtml

来源: OSVDB
名称: 12628
链接:http://www.osvdb.org/12628

来源: SECTRACK
名称: 1012700
链接:http://securitytracker.com/id?1012700

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享