PhpWiki ‘UpLoad.php’ 任意PHP文件上传漏洞

漏洞信息详情

PhpWiki ‘UpLoad.php’ 任意PHP文件上传漏洞

漏洞简介

PhpWiki的UpLoad feature (lib/plugin/UpLoad.php)中存在未限制文件上传漏洞。远程攻击者可以借助该漏洞,上传包含双扩展名的任意PHP文件,比如.php.3。

漏洞公告

参考网址

来源: MISC

链接:https://sourceforge.net/forum/message.php?msg_id=4249177

来源: MLIST

名称: [phpwiki-talk] 20070408 Important UpLoad security fix! was [Fwd: [phpwiki – Open Discussion] RE: upload security risk]

链接:http://www.nabble.com/Important-UpLoad-security-fix%21-was–Fwd%3A–phpwiki—Open-Discussion–RE%3A-upload-security-risk–t3543463.html

来源: GENTOO

名称: GLSA-200705-16

链接:http://www.gentoo.org/security/en/glsa/glsa-200705-16.xml

来源: DEBIAN

名称: DSA-1371

链接:http://www.debian.org/security/2007/dsa-1371

来源: SECUNIA

名称: 26784

链接:http://secunia.com/advisories/26784

来源: SECUNIA

名称: 25307

链接:http://secunia.com/advisories/25307

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享