PT-2005-2976 · Blue Collar Productions · I-Gallery

Seyed Hamid Kashfi

·

Publicado

2005-06-20

·

Atualizado

2016-10-18

·

CVE-2005-2033

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Blue-Collar Productions i-Gallery version 3.3
Description The issue allows remote attackers to read arbitrary files and directories. This is achieved via the folder parameter in the "folderview.asp" file.
Recommendations For version 3.3, consider restricting access to the folderview.asp file until a patch is available. As a temporary workaround, avoid using the folder parameter in the folderview.asp file to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-2033

Produtos afetados

I-Gallery