PT-2007-3962 · Pinkcrow Designs · Magazin+1

Dj7Xpl

·

Publicado

2007-05-13

·

Atualizado

2017-10-11

·

CVE-2007-2643

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PinkCrow Designs Gallery or maGAZIn version 2.0
Description The issue allows remote attackers to read arbitrary files. This is achieved by exploiting a directory traversal vulnerability in the phpThumb.php file, where an attacker can use a .. (dot dot) in the src parameter to access files outside the intended directory.
Recommendations For version 2.0, consider restricting access to the phpThumb.php file or the src parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the src parameter in the affected API endpoint until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2643

Produtos afetados

Gallery
Magazin