vendor:
Snif
by:
Aodrulez
8,8
CVSS
HIGH
Code Injection
N/A
CWE
Product Name: Snif
Affected Version From: 1.5.2
Affected Version To: 1.5.2
Patch Exists: YES
Related CWE: N/A
CPE: a:snif:snif
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Snif – “Any Filetype” Download Exploit
The last line in the code checks the file's extension to make sure its not a php file. This line of code is vulnerable though. The exploit is to use the URL http://www.a.com/snif.php?download=snif.php%00 to bypass all restrictions and let you download a php file.
Mitigation:
Upgrade to the latest version of Snif