PT-2007-1395 · Kubix · Kubix

Blackhawk

·

Publicado

2007-03-06

·

Atualizado

2017-10-11

·

CVE-2006-7117

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Kubix versions 0.7 and earlier
Description The issue allows remote attackers to perform directory traversal attacks. This can be achieved in two ways: (1) by including and executing arbitrary local files via ".." sequences in the theme cookie to "index.php", which is not properly handled by "includes/head.php"; and (2) by reading arbitrary files via ".." sequences in the file parameter in an "add dl" action to "adm index.php". For example, an attacker could read "connect.php" using this method.
Recommendations For Kubix versions 0.7 and earlier, consider disabling access to the "index.php" and "adm index.php" files until a patch is available. Restrict the use of the theme cookie and the file parameter in the "add dl" action to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-7117

Produtos afetados

Kubix