Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHP-Nuke mailattach.php Remote File Upload Vulnerability

The PHP-Nuke mailattach.php script does not properly filter input, potentially allowing files to be uploaded to the system outside the webroot. By including directory traversal characters with the filename to upload, an attacker could possibly overwrite other files on the system or save malicious files to sensitive locations.







 

Privacy Statement
Copyright 2009, SecurityFocus