Project

General

Profile

Actions

Bug #9731

closed

Path Traversal vulnerability in picture widget

Bug #9731: Path Traversal vulnerability in picture widget

Added by Anonymous about 7 years ago. Updated over 6 years ago.

Status:
Duplicate
Priority:
Normal
Assignee:
-
Category:
Dashboard
Target version:
Start date:
09/06/2019
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
All
Affected Architecture:

Description

Vulnerability Description :- The `pfSense` firewall is vulnerable to Remote Code Execution due to `Path Traversal vulnerability`. The file `picture.widget.php` improperly handles `path traversal characters` when uploading an image.

An authenticated remote attacker can exploit this vulnerability by changing the upload file name with traversal characters such as (../) & also replacing the image content with a PHP code inside, along with a valid image header (GIF89a).

Updated by Anonymous about 7 years ago Actions #1

  • Status changed from New to Feedback

Validate widget key by regex before accepting new image

Updated by Anonymous about 7 years ago Actions #2

  • % Done changed from 0 to 100

Applied in changeset commit:42839d824d51cad3a8a55fccb2dc96368568ce8e.

JP Updated by Jim Pingle almost 7 years ago Actions #3

  • Target version changed from 2.5.0 to 2.4.5

JP Updated by Jim Pingle over 6 years ago Actions #4

  • Status changed from Feedback to Duplicate
  • Target version deleted (2.4.5)

Though this had a separate fix applied, I believe it's really the same issue as #9610

JP Updated by Jim Pingle over 6 years ago Actions #5

  • Target version set to 2.4.5
  • Private changed from Yes to No
Actions

Also available in: Atom