OSVDB ID: 7334

Title: IlohaMail Attachment Arbitrary File Create/Overwrite

Info

Disclosure

Feb 06, 2003

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

IlohaMail contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when compose.php fails to check the upload path for file attachments when a message is composed, allowing a malicious user to both place a file on the host in any location which is writeable by the webserver process and overwrite local files. This flaw may lead to a loss of integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 0.7.9 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

IlohaMail

IlohaMail

0.7.9-RC2

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/36218