PT-2005-2217 · Az · Azbb

James Bercegay

·

Published

2005-04-21

·

Updated

2017-07-11

·

CVE-2005-1201

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions AZ Bulletin board (AZbb) versions prior to 1.0.08
Description The issue allows remote authenticated users with administrative privileges to delete arbitrary files by utilizing a .. (dot dot) in the URL to admin avatar.php or admin attachment.php. Additionally, remote attackers can enumerate files via a .. (dot dot) in the attachment parameter to attachment.php, which displays different messages based on whether a file exists or not.
Recommendations For versions prior to 1.0.08, update to version 1.0.08 or later to resolve the issue. As a temporary workaround, consider restricting access to admin avatar.php, admin attachment.php, and attachment.php to minimize the risk of exploitation. Avoid using the attachment parameter in the attachment.php endpoint until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1201

Affected Products

Azbb