header-logo
Suggest Exploit
vendor:
Kwalbum
by:
CWH Underground
7.5
CVSS
HIGH
Arbitrary file upload
434
CWE
Product Name: Kwalbum
Affected Version From: 2.0.2
Affected Version To: 2.0.2
Patch Exists: NO
Related CWE: N/A
CPE: a:kwalbum:kwalbum
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Kwalbum <= 2.0.2 Arbitrary file upload Vulnerabilities

After registeration, users with upload permission can upload php files which can be accessed via a URL. The exploit file format is http://[target]/[path to kwalbum]/[path to store image]/[year]/[month]/shell.php and an example exploit file is http://[target]/[path to kwalbum]/items/08/10/shell.php

Mitigation:

Restrict user access to upload permission and ensure that all uploaded files are scanned for malicious content.
Source

Exploit-DB raw data:

==========================================================
  Kwalbum <= 2.0.2 Arbitrary file upload Vulnerabilities
==========================================================

  ,--^----------,--------,-----,-------^--,
  | |||||||||   `--------'     |          O	.. CWH Underground Hacking Team ..
  `+---------------------------^----------|
    `\_,-------, _________________________|
      / XXXXXX /`|     /
     / XXXXXX /  `\   /
    / XXXXXX /\______(
   / XXXXXX /           
  / XXXXXX /
 (________(             
  `------'


AUTHOR : CWH Underground
DATE   : 3 October 2008
SITE   : cwh.citec.us

##################################################################
APPLICATION : Kwalbum
VERSION     : <= 2.0.2
DOWNLOAD    : http://downloads.sourceforge.net/kwalbum/kwalbum-2.0.2.zip
##################################################################

-----------------
Description:
-----------------
After registeration, you may obtain view, upload or admin permission.
If you obtain an upload permission, you can upload php files which can access as a below example url.

-----------
Exploit:
-----------
[+] upload page: http://[target]/[path to kwalbum]/?p=UploadItems
[+] exploit file format: http://[target]/[path to kwalbum]/[path to store image]/[year]/[month]/shell.php
[+] exploit file example: http://[target]/[path to kwalbum]/items/08/10/shell.php


#####################################################################
Greetz      : ZeQ3uL, BAD $ectors, Snapter, Conan, JabAv0C, Win7dos
Special Thx : asylu3, str0ke, citec.us, milw0rm.com
#####################################################################

# milw0rm.com [2008-10-03]