PT-2008-3296 · Unknown · World Of Phaos
Hacker_Egy
·
Publicado
2008-04-11
·
Atualizado
2017-09-29
·
CVE-2008-1755
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
World of Phaos version 4.0.1
Description
The issue allows remote attackers to read arbitrary files due to a directory traversal vulnerability in the showSource function in showSource.php. This is achieved by using directory traversal sequences in the
file parameter.Recommendations
For World of Phaos version 4.0.1, consider restricting access to the showSource.php file or the showSource function until a patch is available. As a temporary workaround, avoid using the
file parameter in the showSource function to minimize the risk of exploitation.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
World Of Phaos