PT-2005-3614 · Astaro · Astaro Security Linux

Oliver Karow

·

Publicado

2005-08-29

·

Atualizado

2016-10-18

·

CVE-2005-2731

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Astaro Security Linux version 6.0
Description The issue allows remote authenticated Webmin users to read arbitrary files. This is achieved by using a .. (dot dot) in the wfe download parameter to the "index.fpl" endpoint.
Recommendations For Astaro Security Linux version 6.0, consider restricting access to the wfe download parameter in the "index.fpl" endpoint to minimize the risk of exploitation. Avoid using the wfe download parameter with untrusted input until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2731

Produtos afetados

Astaro Security Linux