Arbitrary Upload Vulnerability In Pydio/AjaXplorer 5.0.3 – 3.3.5
Pydio allows you to instantly turn any server into a powerful file sharing platform. Formerly known as AjaXplorer
Description of vulnerability:
There is an unrestricted upload capability, in one of the plugins that is distributed with Pydio 5.0.3 core to AjaXplorer 3.3.5.
An attacker may use this vulnerability to upload arbitrary files in a location that an attacker can control, and will allow remote code execution on the server.
The uploaded file through $_FILES to save_zoho.php will be moved to a path that the user can control with the format parameter passed from the user. Because the file formats allowed are not restricted, and is also used in a move path, this can be used to upload arbitrary files to the server.
Exploiting this vulnerability does not require authentication.
The Common Vulnerabilities and Exposures (CVE) project has assigned CVE-2013-6227 to this issue. This is a candidate for inclusion in the CVE list.
Upgrade to Pydio v5.0.4 or higher. http://pyd.io/pydio-core-5-0-4/