Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14561
HistoryOct 05, 2006 - 12:00 a.m.

[SA22261] Drupal IMCE Module Multiple Vulnerabilities

2006-10-0500:00:00
vulners.com
25

TITLE:
Drupal IMCE Module Multiple Vulnerabilities

SECUNIA ADVISORY ID:
SA22261

VERIFY ADVISORY:
http://secunia.com/advisories/22261/

CRITICAL:
Highly critical

IMPACT:
Manipulation of data, System access

WHERE:
>From remote

SOFTWARE:
IMCE 4.x (module for Drupal)
http://secunia.com/product/12185/

DESCRIPTION:
Some vulnerabilities have been reported in the IMCE Module for
Drupal, which can be exploited by malicious users to delete files or
compromise a vulnerable system.

1) The file deletion functionality does not correctly verify relative
paths before deleting files. Depending on the permissions of the web
server, this can be exploited by malicious users with the "delete
files" permissions to delete arbitrary files.

2) An error exists within the handling of file uploads where a
filename has multiple extensions. This can e.g. be exploited to
execute arbitrary PHP code if a users has the "file upload"
permission.

The vulnerabilities have been reported in versions 4.7 where the CVS
$Id$ field in the imce.module file is older than "$Id: imce.module,v
1.6 2006/09/29 13:50:57 ufku Exp $".

SOLUTION:
Update to the latest version.
http://ftp.osuosl.org/pub/drupal/files/projects/imce-4.7.0.tar.gz

PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.

ORIGINAL ADVISORY:
http://drupal.org/node/87101


About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.