BoastMachine < 3.1 users.inc.php Arbitrary File Upload

Medium Nessus Network Monitor Plugin ID 2897

Synopsis

The remote host is vulnerable to a 'file upload' flaw.

Description

The remote host is running BoastMachine, a blogging software. This version of BoastMachine is vulnerable to a flaw in the users.inc.php script. Specifically, a remote user can pass a specially formatted HTTP request to the BoastMachine script and cause it to upload unsafe files. After upload, the attacker can then execute the files with the permissions of the web server. In addition, the attacker can leave malicious scripts that are executed by unsuspecting users who browse the web page.

Solution

Upgrade to version 3.1 or higher.

See Also

http://www.kernelpanik.org/docs/kernelpanik/bmachines.txt

http://boastology.com/pages/changes.php

Plugin Details

Severity: Medium

ID: 2897

Family: CGI

Published: 2005/05/11

Modified: 2018/07/11

Dependencies: 1442

Nessus ID: 18247

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 6.5

Temporal Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Temporal Vector: CVSS2#E:H/RL:U/RC:ND

CVSSv3

Base Score: 6.2

Temporal Score: 6.2

Vector: CVSS3#AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS3#E:H/RL:U/RC:X

Vulnerability Information

CPE: cpe:/a:boastmachine:boastmachine

Reference Information

CVE: CVE-2005-1580

BID: 13600