Vulnerabilities > CVE-2005-1604 - Unspecified vulnerability in Bugada Andrea PHP Advanced Transfer Manager 1.21
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN bugada-andrea
nessus
Summary
PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as demonstrated using a filename ending in "php.ns", which allows execution of arbitrary PHP code.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses |
NASL id | PHPATM_ARBITRARY_UPLOADS.NASL |
description | The version of PHP Advanced Transfer Manager installed on the remote host allows authenticated users to upload arbitrary files and then run them subject to the privileges of the web server user. It also allows unauthenticated users to read arbitrary files on the remote host and possibly even run arbitrary PHP code, subject to the privileges of the web server user. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18207 |
published | 2005-05-09 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/18207 |
title | PHP Advanced Transfer Manager <= 1.21 Multiple Vulnerabilities |
code |
|
References
- http://seclists.org/lists/bugtraq/2005/May/0075.html
- http://seclists.org/lists/bugtraq/2005/May/0075.html
- http://secunia.com/advisories/15279
- http://secunia.com/advisories/15279
- http://www.osvdb.org/16160
- http://www.osvdb.org/16160
- http://www.securityfocus.com/archive/1/415172
- http://www.securityfocus.com/archive/1/415172
- http://www.securityfocus.com/archive/1/415300/30/0/threaded
- http://www.securityfocus.com/archive/1/415300/30/0/threaded
- http://www.securityfocus.com/bid/13542
- http://www.securityfocus.com/bid/13542