PT-2006-6973 · Bitflu · Bitflux Upload Progress Meter

Publicado

2006-12-07

·

Atualizado

2017-07-29

·

CVE-2006-6361

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Bitflux Upload Progress Meter versions prior to 8276
Description The issue is related to a heap-based buffer overflow in the uploadprogress php rfc1867 file function, which can be triggered by crafted HTTP POST file upload requests. This can lead to a denial of service (crash) or potentially allow remote attackers to execute arbitrary code.
Recommendations For versions prior to 8276, update to version 8276 or later to resolve the issue. As a temporary workaround, consider restricting access to the upload functionality to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-6361

Produtos afetados

Bitflux Upload Progress Meter