PT-2007-6071 · Chupix · Chupix Cms

Gold_M

·

Publicado

2007-09-18

·

Atualizado

2017-09-29

·

CVE-2007-4957

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Chupix CMS version 0.2.3
Description The issue allows remote attackers to read or overwrite arbitrary files, or create arbitrary directories, via directory traversal vulnerabilities in the download.php file. This is achieved by including a .. (dot dot) in the fichier or repertoire parameters for file access, or in the repertoire parameter for directory creation.
Recommendations For Chupix CMS version 0.2.3, as a temporary workaround, consider restricting access to the download.php file until a patch is available. Additionally, restrict the use of the fichier and repertoire parameters to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-4957

Produtos afetados

Chupix Cms