Jetbox One PHP file upload
| jetbox-one-file-upload (16900) |
Description:
Jetbox One could allow a remote attacker to upload malicious PHP files. A remote attacker, with Author privileges in the IMAGES modules, could create a malicious PHP file and upload it via the images upload box, which would allow the attacker to execute code on the vulnerable system, once the file is opened.
Consequences:
Gain Access
Remedy:
No remedy available as of February 6, 2010.
References:
- BugTraq Mailing List, Tue Aug 03 2004 - 23:03:58 CDT: vulnerabilities in JetboxOne CMS.
- BID-10859: Jetbox One Remote Server-Side Script Execution Vulnerability
- BID-23996: Jetbox CMS Arbitrary File Upload Vulnerability
- CVE-2004-1448: Jetbox One 2.0.8 and possibly other versions allow remote attackers with Author privileges in the IMAGES module to upload PHP files and execute arbitrary code.
- CVE-2007-2733: Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload arbitrary scripts via unspecified vectors, which can be accessed in webfiles/. NOTE: this issue might be a duplicate of CVE-2004-1448.
- SA12230: JetBoxOne CMS Arbitrary File Upload Vulnerability
- US-CERT VU#417408: JetboxOne may allow unauthorized users to execute arbitrary code
Platforms Affected:
- Jetbox One Jetbox One 2.0.8
Reported:
Aug 04, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
