vendor:
ImageShack Toolbar
by:
rgod-tsid-pa-he-ru-ka
4.3
CVSS
MEDIUM
Insecure File Upload
434
CWE
Product Name: ImageShack Toolbar
Affected Version From: 4.5.2007
Affected Version To: 4.5.2007
Patch Exists: NO
Related CWE: N/A
CPE: a:imageshack:imageshack_toolbar
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
ImageShack Toolbar 4.5.7 FileUploader Class (ImageShackToolbar.dll) insecure method poc
This vulnerability allows a malicious web page to post arbitrary images on the web from a user hard drive. Images will be visible on ImageShack site, a way for an attacker to retrieve them maybe tag search or by understanding the renaming operation, ex. "_" chars are removed and the "tq2" string is appended. The vulnerability is exploited by using a VBScript to call the BuildSlideShow method of the ImageShackToolbar.dll file, which allows the attacker to upload a file from the user's hard drive.
Mitigation:
Uninstall the ImageShack Toolbar temporarily and use the site functionalities.