PT-2005-3834 · Php · Php Advanced Transfer Manager

Publicado

2005-09-20

·

Atualizado

2008-09-05

·

CVE-2005-2997

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP Advanced Transfer Manager version 1.30
Description The issue allows remote attackers to read arbitrary files due to multiple directory traversal vulnerabilities. This can be achieved by using ".." sequences in the currentdir parameter to "txt.php", or the current dir parameter to "htm.php" or "html.php".
Recommendations For PHP Advanced Transfer Manager version 1.30, consider restricting access to the "txt.php", "htm.php", and "html.php" files until a patch is available. As a temporary workaround, avoid using the currentdir and current dir parameters in the affected API endpoints.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2997

Produtos afetados

Php Advanced Transfer Manager