Secunia Security Advisory - A security issue has been discovered in Max's Image Uploader, which can be exploited by malicious people to compromise a vulnerable system.
2691d58147c0b1b8ee6f2f24fcc0daf78133853fc22856cc5f99f9098c08b051
----------------------------------------------------------------------
Accurate Vulnerability Scanning
No more false positives, no more false negatives
http://secunia.com/vulnerability_scanning/
----------------------------------------------------------------------
TITLE:
Max's Image Uploader File Upload Security Issue
SECUNIA ADVISORY ID:
SA38018
VERIFY ADVISORY:
http://secunia.com/advisories/38018/
DESCRIPTION:
A security issue has been discovered in Max's Image Uploader, which
can be exploited by malicious people to compromise a vulnerable
system.
The security issue is caused due to the index.php script improperly
validating uploaded files. This can be exploited to execute arbitrary
PHP code by uploading a malicious PHP script with multiple
extensions.
Successful exploitation of this vulnerability requires that Apache is
not configured to handle the mime-type for media files with a "pjpeg"
or "jpeg" extension.
SOLUTION:
Restrict access to the index.php script (e.g. via .htaccess).
PROVIDED AND/OR DISCOVERED BY:
indoushka
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
private users keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------