PT-2006-4689 · Kailash Nadh · Boastmachine

Published

2006-07-25

·

Updated

2008-09-05

·

CVE-2006-3830

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Kailash Nadh boastMachine (formerly bMachine) versions 3.1 and earlier
Description The issue concerns the Languages selection in the admin interface, which allows remote authenticated administrators to upload files with arbitrary extensions to the bmc/Inc/Lang directory. This is considered a problem only if there's a likely scenario where local users would open or execute these files, such as malware files with enticing names.
Recommendations For versions 3.1 and earlier, consider restricting access to the bmc/Inc/Lang directory to prevent local users from opening or executing potentially malicious files uploaded through the admin interface. As a temporary workaround, limit the ability of administrators to upload files with arbitrary extensions to mitigate the risk.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3830

Affected Products

Boastmachine