PT-2007-4530 · E Vision · E-Vision Cms

Silentz

·

Publicado

2007-06-18

·

Atualizado

2017-10-19

·

CVE-2007-3251

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: e-Vision CMS versions 2.02 and earlier
Description: The issue allows remote attackers to perform directory traversal attacks. This can be achieved in two ways: (1) by including and executing arbitrary local files via a .. (dot dot) in the adminlang cookie to "admin/functions.php", or (2) by reading arbitrary local files via the img parameter to "admin/show img.php".
Recommendations: For versions 2.02 and earlier, consider disabling access to "admin/functions.php" and "admin/show img.php" until a fix is available. Restrict the use of the adminlang cookie and the img parameter in the affected API endpoints to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3251

Produtos afetados

E-Vision Cms