|
|
Info |
Last Modified |
| 11 months ago |
|
|
|
|
Description |
Photo Organizer contains a flaw that allows a remote user to execute remote commands. The issue is due to Photo Organizer not escaping system() arguments. By uploading a .tar file containing files with crafted names such as "foo;id;bar", the system would execute the commands embedded in the filenames.
|
|
Classification |
Unknown or Incomplete
|
|
Technical |
- This bug only affects bulk uploads (via archive files such as .tar). - The site administrator has to explicitly allow bulk uploads. - This bug does not affect single file uploads provided the original filename is not used in the uploaded filename.
|
|
Solution |
Upgrade to version 2.10 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
Photo Organizer
 |
2.9 |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|