PT-2007-5879 · Gravity Interactive · Ragnarok Online Control Panel
Publicado
2007-09-05
·
Atualizado
2025-03-22
·
CVE-2007-4723
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Ragnarok Online Control Panel version 4.3.4a
Description:
A directory traversal issue allows remote attackers to bypass authentication by using directory traversal sequences in a URI that ends with the name of a publicly available page. This can be achieved with a sequence such as "/...../" and accessing a page like "account manage.php/login.php" to reach protected pages like "account manage.php".
Recommendations:
For Ragnarok Online Control Panel version 4.3.4a, consider restricting access to sensitive pages like "account manage.php" until a patch is available. As a temporary workaround, limit the use of directory traversal sequences in URIs to minimize the risk of exploitation.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ragnarok Online Control Panel