PT-2002-1294 · Wired Community+1 · Wwwthreads+1
Publicado
2002-05-03
·
Atualizado
2008-09-11
·
CVE-2002-0223
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Wired Community Software WWWThreads versions 5.0 through 5.0.9
Infopop UBB.Threads version 5.4
Description
The issue allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends in a different extension.
Recommendations
For Wired Community Software WWWThreads versions 5.0 through 5.0.9, restrict file uploads to only trusted sources and validate file extensions to prevent uploading arbitrary files.
For Infopop UBB.Threads version 5.4, restrict file uploads to only trusted sources and validate file extensions to prevent uploading arbitrary files.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ubb.Threads
Wwwthreads