PT-2007-5638 · Dalai · Dalai Forum

Publicado

2007-08-21

·

Atualizado

2018-10-15

·

CVE-2007-4457

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Dalai Forum version 1.1
Description The issue allows remote attackers to include and execute arbitrary local files. This is achieved by using a .. (dot dot) in the chemin parameter of the forumreply.php file, enabling directory traversal.
Recommendations For Dalai Forum version 1.1, consider restricting access to the chemin parameter in the forumreply.php file to prevent directory traversal attacks. As a temporary workaround, restrict the use of the forumreply.php file until a patch is available.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-4457

Produtos afetados

Dalai Forum