PT-2006-6675 · Dosepa · Dosepa

Craig Heffner

·

Publicado

2006-11-21

·

Atualizado

2024-02-14

·

CVE-2006-6028

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions DoSePa version 1.0.4
Description A directory traversal issue exists, allowing remote attackers to read arbitrary files. This is achieved by using a .. (dot dot) sequence or absolute file path in the file parameter.
Recommendations For version 1.0.4, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the textview.php file to minimize the risk of exploitation. Avoid using absolute file paths or .. (dot dot) sequences in the file parameter until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6028

Produtos afetados

Dosepa