PT-2007-1411 · Php · Upload Tool For Php
CVE-2006-7133
·
Publicado
2007-03-06
·
Atualizado
2024-02-14
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Upload Tool for PHP version 1.0
Description
The issue allows remote attackers to read arbitrary files via directory traversal attacks using ".." sequences or absolute pathnames in the
filename parameter of the /upload/bin/download.php API endpoint.Recommendations
For Upload Tool for PHP version 1.0, consider restricting access to the
/upload/bin/download.php endpoint until a patch is available, and avoid using absolute pathnames or ".." sequences in the filename parameter to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Upload Tool For Php