Acunetix Website Security Scanner GET DEMO
  • Products
    • For Small to Medium BusinessesStandard
    • For Medium to Large OrganizationsPremium
    • For Enterprise OrganizationsAcunetix 360
  • Solutions
    INDUSTRIES
    IT & Telecom Government Financial Services Education Healthcare
    ROLES
    CTO & CISO Engineering Manager Security Engineer DevSecOps
  • Pricing
  • Customers
  • Resources
    • Blog
    • Web Security
    • Product Releases
    • Product Articles
    • Support
  • GET DEMO
ACUNETIX SUPPORT Web Vulnerabilities Index

Arbitrary local file read via file upload

Description

Acunetix uploaded a ZIP file containing a symlink to /etc/passwd. It looks like that web application processed this file and returned the contents of /etc/passwd in response.

Remediation

The web application should filter symlinks included inside ZIP files.

References

Reading local files from Facebook's server

Related Vulnerabilities

WordPress Plugin Ultimate Member-User Profile & Membership Arbitrary File Upload (1.0.83)

WordPress Plugin Wallable-Social Networking Arbitrary File Upload (1.1)

WordPress Plugin Carousel slideshow 'upload.php' Arbitrary File Upload (3.9)

WordPress Plugin Flip Book 'php.php' Arbitrary File Upload (1.0)

WordPress Plugin Simple Slide Show TimThumb Arbitrary File Upload (1.0)

Severity

High

Classification

CWE-200 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Tags

Unauthenticated File Upload

Take action and discover your vulnerabilities

Get a Demo
Product Information
  • AcuSensor Technology
  • AcuMonitor Technology
  • Network Security Scanner
  • Acunetix Integrations
  • Vulnerability Scanner
Use Cases
  • Penetration Testing Software
  • Website Security Scanner
  • External Vulnerability Scanner
  • Web Application Security
  • Vulnerability Management Software
Website Security
  • Cross-site Scripting
  • SQL Injection
  • Reflected XSS
  • CSRF Attacks
  • Directory Traversal
Learn More
  • White Papers
  • TLS Security
  • WordPress Security
  • Web Service Security
  • Prevent SQL Injection
Company
  • About Us
  • Customers
  • Become a Partner
  • Jobs
  • Contact
Documentation
  • Case Studies
  • Support
  • Videos
  • Web Vulnerabilities
  • Webinars
  • Acunetix Online Login
  • Subscription Services Agreement
  • Data Protection Policy
  • Privacy Policy
  • Sitemap
  • Find us on Facebook
  • Follow us on Twiter
  • Follow us on LinkedIn

© Acunetix, 2020