|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
YaPiG contains a flaw that allows an authenticated user to create and delete arbitrary directories outside of the gallery directory. The issue is due to the upload.php script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the dir variable.
|
|
Classification |
Location:
Local Access Required,
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
OSVDB:
Web Related
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
YaPiG
 |
0.92.2 |
0.93 |
0.94 |
|
|
|
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|