PT-2005-3614 · Astaro · Astaro Security Linux
Oliver Karow
·
Publicado
2005-08-29
·
Atualizado
2016-10-18
·
CVE-2005-2731
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Astaro Security Linux version 6.0
Description
The issue allows remote authenticated Webmin users to read arbitrary files. This is achieved by using a .. (dot dot) in the
wfe download parameter to the "index.fpl" endpoint.Recommendations
For Astaro Security Linux version 6.0, consider restricting access to the
wfe download parameter in the "index.fpl" endpoint to minimize the risk of exploitation. Avoid using the wfe download parameter with untrusted input until the issue is resolved.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Astaro Security Linux