PT-2008-1639 · Uber · Uber Uploader
Published
2008-01-08
·
Updated
2018-10-15
·
CVE-2007-6676
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Uber Uploader versions 5.3.6 and earlier
Description
The default configuration of Uber Uploader does not block uploads of potentially dangerous file extensions, such as
.html and .asp. This allows remote attackers to upload these files via API endpoints like "uu file upload.php" and "uber uploader file.php", which are related to "uu file upload.js" and "uber uploader file.js", respectively.Recommendations
For Uber Uploader versions 5.3.6 and earlier, consider adding restrictions to block uploads of potentially dangerous file extensions, such as
.html and .asp, to prevent remote attackers from exploiting this issue. As a temporary workaround, restrict access to the "uu file upload.php" and "uber uploader file.php" API endpoints until a more permanent solution is implemented.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uber Uploader