blueimp jQuery Arbitrary File Upload

Discussion in 'News Aggregator' started by Packet Storm, 6 Nov 2018.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits an arbitrary file upload in the sample PHP upload handler for blueimp's jQuery File Upload widget in versions 9.22.0 and below. Due to a default configuration in Apache 2.3.9+, the widget's .htaccess file may be disabled, enabling exploitation of this vulnerability. This vulnerability has been exploited in the wild since at least 2015 and was publicly disclosed to the vendor in 2018. It has been present since the .htaccess change in Apache 2.3.9. This Metasploit module provides a generic exploit against the jQuery widget.

    Continue reading...
     

Share This Page

Loading...