PT-2005-2217 · Az · Azbb
James Bercegay
·
Published
2005-04-21
·
Updated
2017-07-11
·
CVE-2005-1201
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
AZ Bulletin board (AZbb) versions prior to 1.0.08
Description
The issue allows remote authenticated users with administrative privileges to delete arbitrary files by utilizing a .. (dot dot) in the URL to
admin avatar.php or admin attachment.php. Additionally, remote attackers can enumerate files via a .. (dot dot) in the attachment parameter to attachment.php, which displays different messages based on whether a file exists or not.Recommendations
For versions prior to 1.0.08, update to version 1.0.08 or later to resolve the issue. As a temporary workaround, consider restricting access to
admin avatar.php, admin attachment.php, and attachment.php to minimize the risk of exploitation. Avoid using the attachment parameter in the attachment.php endpoint until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Azbb