PT-2007-6777 · Ispworker · Ispworker

Gold_M

·

Publicado

2007-11-05

·

Atualizado

2017-09-29

·

CVE-2007-5813

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ISPworker version 1.21
Description The issue concerns multiple directory traversal vulnerabilities in the download.php file. Remote attackers can exploit this to read arbitrary files by including a .. (dot dot) in the ticketid and filename parameters.
Recommendations For ISPworker version 1.21, consider restricting access to the download.php file until a patch is available, and avoid using the ticketid and filename parameters in this file to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5813

Produtos afetados

Ispworker