Olate Download 3.4.2 ~ userupload.php ~ Upload Executable Files
Posted by imei on September 1st, 2007——-Summary——
Software: Olate Download
Sowtware’s Web Site: http://www.olate.co.uk/
Versions: 3.4.2
Class: Remote
Status: Patched
Exploit: Available
Solution: Not Available
Discovered by: imei Addmimistrator
Risk Level: High
——Description—–
Olate download is prone to Upload executable file in uploads folder, If admin specified users can upload files.
Olate does not check Extension of uploaded file, and store them with its original extension. So uploading .php and .cgi and etc. […]