PT-2007-3757 · Imageview · Imageview
Dnx
·
Publicado
2007-05-02
·
Atualizado
2017-10-11
·
CVE-2007-2425
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Imageview version 5.3
Description
A directory traversal issue exists, allowing remote attackers to read arbitrary files. This is achieved by using a .. (dot dot) in the
album parameter of the fileview.php file.Recommendations
For Imageview version 5.3, consider restricting access to the fileview.php file until a patch is available, or apply configuration changes to prevent directory traversal attacks, such as validating and sanitizing user input for the
album parameter.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Imageview