PT-2006-4689 · Kailash Nadh · Boastmachine
Published
2006-07-25
·
Updated
2008-09-05
·
CVE-2006-3830
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Kailash Nadh boastMachine (formerly bMachine) versions 3.1 and earlier
Description
The issue concerns the Languages selection in the admin interface, which allows remote authenticated administrators to upload files with arbitrary extensions to the bmc/Inc/Lang directory. This is considered a problem only if there's a likely scenario where local users would open or execute these files, such as malware files with enticing names.
Recommendations
For versions 3.1 and earlier, consider restricting access to the bmc/Inc/Lang directory to prevent local users from opening or executing potentially malicious files uploaded through the admin interface. As a temporary workaround, limit the ability of administrators to upload files with arbitrary extensions to mitigate the risk.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Boastmachine