PT-2002-1294 · Wired Community+1 · Wwwthreads+1
Published
2002-05-03
·
Updated
2008-09-11
·
CVE-2002-0223
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Wired Community Software WWWThreads versions 5.0 through 5.0.9
Infopop UBB.Threads version 5.4
Description
The issue allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends in a different extension.
Recommendations
For Wired Community Software WWWThreads versions 5.0 through 5.0.9, restrict file uploads to only trusted sources and validate file extensions to prevent uploading arbitrary files.
For Infopop UBB.Threads version 5.4, restrict file uploads to only trusted sources and validate file extensions to prevent uploading arbitrary files.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ubb.Threads
Wwwthreads