Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Zeroboard Arbitrary File Upload Vulnerability

Zeroboard is prone to an arbitrary file-upload vulnerability.

An attacker can exploit this vulnerability to upload a malicious '.htaccess' file that will remove restrictions on further file-uploads and executions.

Note that to exploit this vulnerability, the Apache 'mod_mime' module must be installed and the web directory must be configured with the Apache 'AllowOverride All' or 'AllowOverride FileInfo' webserver directives.

This issue affects versions 4.1pl8 and prior.







 

Privacy Statement
Copyright 2009, SecurityFocus