Description
|
|
Multiple vulnerabilities have been identified in Easy File Sharing Web Server, which could be exploited by remote attackers to cause a denial of service or execute arbitrary commands and scripting code.
The first issue is due to a format string error in the logging functionality that does not properly handle specially crafted HTTP requests, which could be exploited by remote attackers to crash or compromise a vulnerable server.
The second flaw is due to input validation errors in the "upload.ghp" and "createfolder.ghp" scripts that do not validate the "upload_title" and "folder_des" parameters (i.e. the "Description" field), which could be exploited by attackers to cause malicious scripting code to be executed by the user's browser in the security context of an affected Web site.
|