MoniWiki file extensions file upload
| moniwiki-file-upload (18493) |
Description:
MoniWiki is a Wiki Web program. MoniWiki version 1.0.9.2 and possibly other versions could allow a remote attacker to upload malicious files, caused by improper handling of file uploads when a filename contains multiple file extensions. If MoniWiki is running on Apache HTTP server and the mod_mime and the mod_php modules are installed, a remote attacker could exploit this vulnerability to upload malicious files to the Web root directory, and possibly execute arbitrary code on the system.
Note: JSBoard version 1.3.11 and 2.0.8 are also affected by this vulnerability.
Consequences:
File Manipulation
Remedy:
For MoniWiki:
Reportedly, this vulnerability has been fixed in the CVS repository. See References.
For JSBoard:
Upgrade to the latest version (1.3.13 or 2.0.9 or later), available from the JSBoard Download Web page. See References.
As a workaround, disable the mod_mime module.
References:
- BugTraq Mailing List, Wed Dec 15 2004 - 20:43:12 CST: STG Security Advisory: [SSA-20041215-19] Vulnerability of uploading files with multiple extensions in MediaWiki.
- Full-Disclosure Mailing List, Wed Dec 15 2004 - 05:08:04 CST: STG Security Advisory: [SSA-20041215-15] Vulnerability of uploading files with multiple extensions in MoniWiki.
- JSBoard Download Web page: KLDP.net Project File List.
- SourceForge.net: Project: moniwiki: Summary.
- SourceForge.net: Project: moniwiki: CVS.
- BID-11951: MoniWiki Remote Server-Side Script Execution Vulnerability
- BID-11983: JSBoard Remote Arbitrary Script Upload Vulnerability
- BID-11985: MediaWiki Remote Arbitrary Script Upload Vulnerability
- CVE-2004-1405: MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
- CVE-2004-1545: UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.
- SA13478: MoniWiki Multiple File Extensions Script Upload Vulnerability
Platforms Affected:
- MoniWiki MoniWiki 1.0.9.2
Reported:
Dec 15, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
