Title: YaPiG upload.php dir Variable Arbitrary Directory Manipulation
Info
Disclosure
Jun 04, 2005
Discovery
May 29, 2005
Dates
Exploit
Jun 04, 2005
Solution
Unknown
Description
YaPiG contains a flaw that allows an authenticated user to create and delete arbitrary directories outside of the gallery directory. The issue is due to the upload.php script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the dir variable.
Classification
Location:
Local Access Required,
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Public
OSVDB:
Web Related
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.