PT-2002-1294 · Wired Community+1 · Wwwthreads+1

Published

2002-05-03

·

Updated

2008-09-11

·

CVE-2002-0223

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Wired Community Software WWWThreads versions 5.0 through 5.0.9 Infopop UBB.Threads version 5.4
Description The issue allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends in a different extension.
Recommendations For Wired Community Software WWWThreads versions 5.0 through 5.0.9, restrict file uploads to only trusted sources and validate file extensions to prevent uploading arbitrary files. For Infopop UBB.Threads version 5.4, restrict file uploads to only trusted sources and validate file extensions to prevent uploading arbitrary files.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0223

Affected Products

Ubb.Threads
Wwwthreads