PT-2006-6973 · Bitflu · Bitflux Upload Progress Meter
Publicado
2006-12-07
·
Atualizado
2017-07-29
·
CVE-2006-6361
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Bitflux Upload Progress Meter versions prior to 8276
Description
The issue is related to a heap-based buffer overflow in the
uploadprogress php rfc1867 file function, which can be triggered by crafted HTTP POST file upload requests. This can lead to a denial of service (crash) or potentially allow remote attackers to execute arbitrary code.Recommendations
For versions prior to 8276, update to version 8276 or later to resolve the issue. As a temporary workaround, consider restricting access to the upload functionality to minimize the risk of exploitation.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bitflux Upload Progress Meter