PT-2008-1639 · Uber · Uber Uploader

Published

2008-01-08

·

Updated

2018-10-15

·

CVE-2007-6676

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Uber Uploader versions 5.3.6 and earlier
Description The default configuration of Uber Uploader does not block uploads of potentially dangerous file extensions, such as .html and .asp. This allows remote attackers to upload these files via API endpoints like "uu file upload.php" and "uber uploader file.php", which are related to "uu file upload.js" and "uber uploader file.js", respectively.
Recommendations For Uber Uploader versions 5.3.6 and earlier, consider adding restrictions to block uploads of potentially dangerous file extensions, such as .html and .asp, to prevent remote attackers from exploiting this issue. As a temporary workaround, restrict access to the "uu file upload.php" and "uber uploader file.php" API endpoints until a more permanent solution is implemented.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6676

Affected Products

Uber Uploader