PT-2006-1754 · Imagevue · Imagevue
Publicado
2006-02-15
·
Atualizado
2017-07-20
·
CVE-2006-0700
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
imageVue version 16.1
Description
The issue allows remote attackers to obtain folder permission settings by making a direct request to "dir.php", which returns an XML document listing folders and their permissions.
Recommendations
For imageVue version 16.1, consider restricting access to the "dir.php" endpoint to prevent unauthorized disclosure of folder permission settings. As a temporary workaround, consider disabling the
dir.php endpoint until a patch is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Imagevue