PT-2007-7103 · Learnloop · Learnloop

Gold_M

·

Publicado

2007-12-04

·

Atualizado

2017-09-29

·

CVE-2007-6214

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions LearnLoop version 2.0 beta7
Description A directory traversal issue exists, allowing remote attackers to read arbitrary files by utilizing a .. (dot dot) in the sFilePath parameter of the include/file download.php file. This issue can be exploited if the product is configured but has no files in the database.
Recommendations For LearnLoop version 2.0 beta7, consider restricting access to the include/file download.php file or the sFilePath parameter to minimize the risk of exploitation. Avoid using the sFilePath parameter with unvalidated input until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6214

Produtos afetados

Learnloop