PT-2002-1294 · Wired Community+1 · Wwwthreads+1

Publicado

2002-05-03

·

Atualizado

2008-09-11

·

CVE-2002-0223

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Wired Community Software WWWThreads versions 5.0 through 5.0.9 Infopop UBB.Threads version 5.4
Description The issue allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends in a different extension.
Recommendations For Wired Community Software WWWThreads versions 5.0 through 5.0.9, restrict file uploads to only trusted sources and validate file extensions to prevent uploading arbitrary files. For Infopop UBB.Threads version 5.4, restrict file uploads to only trusted sources and validate file extensions to prevent uploading arbitrary files.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0223

Produtos afetados

Ubb.Threads
Wwwthreads