PT-2004-2322 · Unknown · Singapore Image Gallery Web Application
Publicado
2004-12-31
·
Atualizado
2017-07-11
·
CVE-2004-1407
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
singapore Image Gallery Web Application version 0.9.10
Description:
The issue allows remote attackers to read or delete arbitrary files. This can be achieved through directory traversal vulnerabilities, specifically by exploiting the
showThumb method in thumb.php to read files or by exploiting admin.class.php to delete files.Recommendations:
For version 0.9.10, consider restricting access to the
thumb.php and admin.class.php files until a patch is available. As a temporary workaround, avoid using the showThumb method in thumb.php and restrict the functionality of admin.class.php to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Singapore Image Gallery Web Application