PT-2006-2998 · Sl Site · Sl Site

Publicado

2006-04-25

·

Atualizado

2017-07-20

·

CVE-2006-2014

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SL site version 1.0
Description A directory traversal issue exists due to improper handling of the rep parameter in gallerie.php, allowing remote attackers to list images in arbitrary directories by using ".." sequences. This could potentially lead to resultant XSS from an error message.
Recommendations For SL site version 1.0, as a temporary workaround, consider restricting access to the gallerie.php file until a proper fix is applied, and avoid using the rep parameter in a way that could facilitate directory traversal attacks.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2014

Produtos afetados

Sl Site