vendor:
HTTP_Upload
by:
John Page AKA Hyp3rlinx
8,8
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: HTTP_Upload
Affected Version From: 1.0.0b3
Affected Version To: 1.0.0b3
Patch Exists: YES
Related CWE: N/A
CPE: a:pear:http_upload:1.0.0b3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
PEAR HTTP_UPLOAD Arbitrary File Upload
The HTTP_Upload package is vulnerable to an arbitrary file upload vulnerability. The package comes with an "upload_example.php" file to test the package, when uploading a "restricted" PHP file user will get message like "Unauthorized file transmission". However, the "upload_example.php" will accept any file extension, even if it is not in the "Upload.php" list of allowed extensions. This is due to the fact that the "Upload.php" code does not properly check for case sensitive file extensions. An attacker can exploit this vulnerability to upload malicious files to the server, which can be used to gain remote code execution.
Mitigation:
Upgrade to the latest version of the HTTP_Upload package.