PT-2007-3618 · Sencha · Extjs

Alkomandoz Hacker

·

Publicado

2007-04-26

·

Atualizado

2017-10-11

·

CVE-2007-2285

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ext JS version 1.0 alpha1
Description A directory traversal issue exists, allowing remote attackers to read arbitrary files by using a .. (dot dot) in the feed parameter of the examples/layout/feed-proxy.php file. It is noted that this issue might be platform dependent.
Recommendations For Ext JS version 1.0 alpha1, as a temporary workaround, consider restricting access to the feed-proxy.php file until a patch is available. Avoid using the feed parameter in the affected API endpoint until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2285

Produtos afetados

Extjs