PT-2006-6987 · Sfm · Simple File Manager
Flame
·
Publicado
2006-12-07
·
Atualizado
2017-10-19
·
CVE-2006-6376
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Simple File Manager (SFM) version 0.24a
Description
The issue allows remote attackers to perform directory traversal attacks using ".." sequences. This can be used to read arbitrary files via the
filename parameter in a "download" action, delete arbitrary files via the delete parameter, and modify arbitrary files via the edit parameter. These actions can potentially be leveraged to execute arbitrary code.Recommendations
For Simple File Manager (SFM) version 0.24a, consider restricting access to the
fm.php file until a patch is available. As a temporary workaround, avoid using the filename, delete, and edit parameters in the affected actions to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Simple File Manager