arslancb / clipbucketv3

Clipbucket - An open source social networking and video sharing php software/script/application
Other
47 stars 86 forks source link

Remote file inclusion vulnerability #9

Open alxbrd opened 11 years ago

alxbrd commented 11 years ago

Unescaped POST data is written to the disk in this file:

clipbucket/upload/admin_area/charts/ofc-library/ofc_upload_image.php

oradwell commented 10 years ago

Details about the vulnerability: http://www.securityfocus.com/bid/37314

Removing the file cause no problems since it's not being referenced anywhere else in the codebase